PT-2021-20095 · Manageengine · Zoho Manageengine Adselfservice Plus
Published
2021-08-09
·
Updated
2024-08-04
·
CVE-2021-33256
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ManageEngine ADSelfService Plus version 6.1 Build No: 6101
Description
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus can be exploited by an unauthenticated user. The
j username parameter seems to be vulnerable, and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as a CSV file. The vendor disputes this issue, claiming it is not a valid vulnerability in their product.Recommendations
For ManageEngine ADSelfService Plus version 6.1 Build No: 6101, consider disabling the export of "User Attempts Audit Report" as a CSV file to minimize the risk of exploitation. Restrict access to the login panel to reduce the potential for unauthenticated users to exploit the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Adselfservice Plus