CVE-2021-27214
19.02.2021, 19:15
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_adselfservice_plus | 6.0 |
zohocorp | manageengine_adselfservice_plus | 6.0:6000 |
zohocorp | manageengine_adselfservice_plus | 6.0:6001 |
zohocorp | manageengine_adselfservice_plus | 6.0:6002 |
zohocorp | manageengine_adselfservice_plus | 6.0:6003 |
zohocorp | manageengine_adselfservice_plus | 6.0:6004 |
zohocorp | manageengine_adselfservice_plus | 6.0:6005 |
zohocorp | manageengine_adselfservice_plus | 6.0:6006 |
zohocorp | manageengine_adselfservice_plus | 6.0:6007 |
zohocorp | manageengine_adselfservice_plus | 6.0:6008 |
zohocorp | manageengine_adselfservice_plus | 6.0:6009 |
zohocorp | manageengine_adselfservice_plus | 6.0:6012 |
zohocorp | manageengine_adselfservice_plus | 6.0:6013 |
𝑥
= Vulnerable software versions
References