PT-2019-15395 · Zoho · Zoho Manageengine Adselfservice Plus
Pornsook Kornkitichai
·
Published
2019-11-06
·
Updated
2019-11-08
·
CVE-2019-18411
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine ADSelfService Plus versions 5.x through 5803
Description
The issue allows attackers to modify users' profile information unintentionally, including email and mobile phone details, through a CSRF attack on the users' profile information page. This could further enable attackers to use the reset password function, potentially allowing them to control the system and redirect authentication codes to channels they own.
Recommendations
For versions 5.x through 5803, as a temporary workaround, consider restricting access to the users' profile information page and the reset password function until a patch is available. Additionally, avoid using the reset password feature in the affected versions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Adselfservice Plus