Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-538j-xxfp-r55q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.

EPSS

Процентиль: 39%
0.00174
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.

EPSS

Процентиль: 39%
0.00174
Низкий