PT-2019-15395 · Zoho · Zoho Manageengine Adselfservice Plus

Pornsook Kornkitichai

·

Published

2019-11-06

·

Updated

2019-11-08

·

CVE-2019-18411

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ADSelfService Plus versions 5.x through 5803
Description The issue allows attackers to modify users' profile information unintentionally, including email and mobile phone details, through a CSRF attack on the users' profile information page. This could further enable attackers to use the reset password function, potentially allowing them to control the system and redirect authentication codes to channels they own.
Recommendations For versions 5.x through 5803, as a temporary workaround, consider restricting access to the users' profile information page and the reset password function until a patch is available. Additionally, avoid using the reset password feature in the affected versions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18411

Affected Products

Zoho Manageengine Adselfservice Plus