CVE-2019-18411

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
zohocorpmanageengine_adselfservice_plus
5.0:5000
zohocorpmanageengine_adselfservice_plus
5.0:5001
zohocorpmanageengine_adselfservice_plus
5.0:5002
zohocorpmanageengine_adselfservice_plus
5.0:5010
zohocorpmanageengine_adselfservice_plus
5.0:5011
zohocorpmanageengine_adselfservice_plus
5.0:5020
zohocorpmanageengine_adselfservice_plus
5.0:5021
zohocorpmanageengine_adselfservice_plus
5.0:5022
zohocorpmanageengine_adselfservice_plus
5.0:5030
zohocorpmanageengine_adselfservice_plus
5.0:5032
zohocorpmanageengine_adselfservice_plus
5.0:5040
zohocorpmanageengine_adselfservice_plus
5.0:5041
zohocorpmanageengine_adselfservice_plus
5.1:5100
zohocorpmanageengine_adselfservice_plus
5.1:5101
zohocorpmanageengine_adselfservice_plus
5.1:5102
zohocorpmanageengine_adselfservice_plus
5.1:5103
zohocorpmanageengine_adselfservice_plus
5.1:5104
zohocorpmanageengine_adselfservice_plus
5.1:5105
zohocorpmanageengine_adselfservice_plus
5.1:5106
zohocorpmanageengine_adselfservice_plus
5.1:5107
zohocorpmanageengine_adselfservice_plus
5.1:5108
zohocorpmanageengine_adselfservice_plus
5.1:5109
zohocorpmanageengine_adselfservice_plus
5.1:5110
zohocorpmanageengine_adselfservice_plus
5.1:5111
zohocorpmanageengine_adselfservice_plus
5.1:5112
zohocorpmanageengine_adselfservice_plus
5.1:5113
zohocorpmanageengine_adselfservice_plus
5.1:5114
zohocorpmanageengine_adselfservice_plus
5.1:5115
zohocorpmanageengine_adselfservice_plus
5.2:5200
zohocorpmanageengine_adselfservice_plus
5.2:5201
zohocorpmanageengine_adselfservice_plus
5.2:5202
zohocorpmanageengine_adselfservice_plus
5.2:5203
zohocorpmanageengine_adselfservice_plus
5.2:5204
zohocorpmanageengine_adselfservice_plus
5.2:5205
zohocorpmanageengine_adselfservice_plus
5.2:5206
zohocorpmanageengine_adselfservice_plus
5.2:5207
zohocorpmanageengine_adselfservice_plus
5.3:5300
zohocorpmanageengine_adselfservice_plus
5.3:5301
zohocorpmanageengine_adselfservice_plus
5.3:5302
zohocorpmanageengine_adselfservice_plus
5.3:5303
zohocorpmanageengine_adselfservice_plus
5.3:5304
zohocorpmanageengine_adselfservice_plus
5.3:5305
zohocorpmanageengine_adselfservice_plus
5.3:5306
zohocorpmanageengine_adselfservice_plus
5.3:5307
zohocorpmanageengine_adselfservice_plus
5.3:5308
zohocorpmanageengine_adselfservice_plus
5.3:5309
zohocorpmanageengine_adselfservice_plus
5.3:5310
zohocorpmanageengine_adselfservice_plus
5.3:5311
zohocorpmanageengine_adselfservice_plus
5.3:5312
zohocorpmanageengine_adselfservice_plus
5.3:5313
zohocorpmanageengine_adselfservice_plus
5.3:5314
zohocorpmanageengine_adselfservice_plus
5.3:5315
zohocorpmanageengine_adselfservice_plus
5.3:5316
zohocorpmanageengine_adselfservice_plus
5.3:5317
zohocorpmanageengine_adselfservice_plus
5.3:5318
zohocorpmanageengine_adselfservice_plus
5.3:5319
zohocorpmanageengine_adselfservice_plus
5.3:5320
zohocorpmanageengine_adselfservice_plus
5.3:5321
zohocorpmanageengine_adselfservice_plus
5.3:5322
zohocorpmanageengine_adselfservice_plus
5.3:5323
zohocorpmanageengine_adselfservice_plus
5.3:5324
zohocorpmanageengine_adselfservice_plus
5.3:5325
zohocorpmanageengine_adselfservice_plus
5.3:5326
zohocorpmanageengine_adselfservice_plus
5.3:5327
zohocorpmanageengine_adselfservice_plus
5.3:5328
zohocorpmanageengine_adselfservice_plus
5.3:5329
zohocorpmanageengine_adselfservice_plus
5.3:5330
zohocorpmanageengine_adselfservice_plus
5.4:5400
zohocorpmanageengine_adselfservice_plus
5.5:5500
zohocorpmanageengine_adselfservice_plus
5.5:5501
zohocorpmanageengine_adselfservice_plus
5.5:5502
zohocorpmanageengine_adselfservice_plus
5.5:5503
zohocorpmanageengine_adselfservice_plus
5.5:5504
zohocorpmanageengine_adselfservice_plus
5.5:5505
zohocorpmanageengine_adselfservice_plus
5.5:5506
zohocorpmanageengine_adselfservice_plus
5.5:5507
zohocorpmanageengine_adselfservice_plus
5.5:5508
zohocorpmanageengine_adselfservice_plus
5.5:5509
zohocorpmanageengine_adselfservice_plus
5.5:5510
zohocorpmanageengine_adselfservice_plus
5.5:5511
zohocorpmanageengine_adselfservice_plus
5.5:5512
zohocorpmanageengine_adselfservice_plus
5.5:5513
zohocorpmanageengine_adselfservice_plus
5.5:5514
zohocorpmanageengine_adselfservice_plus
5.5:5515
zohocorpmanageengine_adselfservice_plus
5.5:5516
zohocorpmanageengine_adselfservice_plus
5.5:5517
zohocorpmanageengine_adselfservice_plus
5.5:5518
zohocorpmanageengine_adselfservice_plus
5.5:5519
zohocorpmanageengine_adselfservice_plus
5.5:5520
zohocorpmanageengine_adselfservice_plus
5.5:5521
zohocorpmanageengine_adselfservice_plus
5.6:5600
zohocorpmanageengine_adselfservice_plus
5.6:5601
zohocorpmanageengine_adselfservice_plus
5.6:5602
zohocorpmanageengine_adselfservice_plus
5.6:5603
zohocorpmanageengine_adselfservice_plus
5.6:5604
zohocorpmanageengine_adselfservice_plus
5.6:5605
zohocorpmanageengine_adselfservice_plus
5.6:5606
zohocorpmanageengine_adselfservice_plus
5.6:5607
zohocorpmanageengine_adselfservice_plus
5.7:5702
zohocorpmanageengine_adselfservice_plus
5.7:5704
zohocorpmanageengine_adselfservice_plus
5.7:5705
zohocorpmanageengine_adselfservice_plus
5.7:5706
zohocorpmanageengine_adselfservice_plus
5.7:5707
zohocorpmanageengine_adselfservice_plus
5.7:5708
zohocorpmanageengine_adselfservice_plus
5.7:5709
zohocorpmanageengine_adselfservice_plus
5.7:5710
zohocorpmanageengine_adselfservice_plus
5.8:5800
zohocorpmanageengine_adselfservice_plus
5.8:5801
zohocorpmanageengine_adselfservice_plus
5.8:5802
zohocorpmanageengine_adselfservice_plus
5.8:5803
𝑥
= Vulnerable software versions