PT-2019-10154 · Zoho Manageengine · Adselfservice Plus
Dominique Righetto
·
Published
2019-01-03
·
Updated
2019-05-13
·
CVE-2018-20664
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Zoho ManageEngine ADSelfService Plus versions 5.x before build 5701
Description:
The issue is related to an XML External Entity (XXE) vulnerability. This occurs when an uploaded product license is processed, allowing potential exploitation.
Recommendations:
For Zoho ManageEngine ADSelfService Plus versions 5.x before build 5701, update to build 5701 or later to resolve the issue.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adselfservice Plus