PT-2019-15395 · Zoho · Zoho Manageengine Adselfservice Plus
Pornsook Kornkitichai
·
Publicado
2019-11-06
·
Atualizado
2019-11-08
·
CVE-2019-18411
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine ADSelfService Plus versions 5.x through 5803
Description
The issue allows attackers to modify users' profile information unintentionally, including email and mobile phone details, through a CSRF attack on the users' profile information page. This could further enable attackers to use the reset password function, potentially allowing them to control the system and redirect authentication codes to channels they own.
Recommendations
For versions 5.x through 5803, as a temporary workaround, consider restricting access to the users' profile information page and the reset password function until a patch is available. Additionally, avoid using the reset password feature in the affected versions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zoho Manageengine Adselfservice Plus