CVE-2025-1723
03.03.2025, 08:15
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to thesession mishandling. Valid account holders in the setup only have the potential to exploit this bug.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_adselfservice_plus | 𝑥 < 6.5 |
zohocorp | manageengine_adselfservice_plus | 6.5:6500 |
zohocorp | manageengine_adselfservice_plus | 6.5:6501 |
zohocorp | manageengine_adselfservice_plus | 6.5:6502 |
zohocorp | manageengine_adselfservice_plus | 6.5:6503 |
zohocorp | manageengine_adselfservice_plus | 6.5:6504 |
zohocorp | manageengine_adselfservice_plus | 6.5:6505 |
zohocorp | manageengine_adselfservice_plus | 6.5:6506 |
zohocorp | manageengine_adselfservice_plus | 6.5:6507 |
zohocorp | manageengine_adselfservice_plus | 6.5:6508 |
zohocorp | manageengine_adselfservice_plus | 6.5:6509 |
zohocorp | manageengine_adselfservice_plus | 6.5:6510 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration