PT-2019-10154 · Zoho Manageengine · Adselfservice Plus

Dominique Righetto

·

Published

2019-01-03

·

Updated

2019-05-13

·

CVE-2018-20664

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zoho ManageEngine ADSelfService Plus versions 5.x before build 5701
Description: The issue is related to an XML External Entity (XXE) vulnerability. This occurs when an uploaded product license is processed, allowing potential exploitation.
Recommendations: For Zoho ManageEngine ADSelfService Plus versions 5.x before build 5701, update to build 5701 or later to resolve the issue.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20664

Affected Products

Adselfservice Plus