PT-2019-15395 · Zoho · Zoho Manageengine Adselfservice Plus

Pornsook Kornkitichai

·

Publicado

2019-11-06

·

Atualizado

2019-11-08

·

CVE-2019-18411

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ADSelfService Plus versions 5.x through 5803
Description The issue allows attackers to modify users' profile information unintentionally, including email and mobile phone details, through a CSRF attack on the users' profile information page. This could further enable attackers to use the reset password function, potentially allowing them to control the system and redirect authentication codes to channels they own.
Recommendations For versions 5.x through 5803, as a temporary workaround, consider restricting access to the users' profile information page and the reset password function until a patch is available. Additionally, avoid using the reset password feature in the affected versions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-18411

Produtos afetados

Zoho Manageengine Adselfservice Plus