CVE-2019-18411 Information
Feb 14, 2021
cve
Description
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users’ profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information such as email and mobile phone unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://gist.github.com/aliceicl/e32fb4a17277c7db9e0256185ac03dae
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: