
CVE-2021-20147
https://notcve.org/view.php?id=CVE-2021-20147
03 Jan 2022 — ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists. ManageEngine ADSelfService Plus versiones anteriores a la compilación 6116, contiene una discrepancia de respuesta observable en la operación UMCP de la ChangePasswordAPI. Esto permite a un atacante remoto no autenticado determinar si se presenta un usuario de dominio de W... • https://www.tenable.com/security/research/tra-2021-52 • CWE-203: Observable Discrepancy •

CVE-2021-37422
https://notcve.org/view.php?id=CVE-2021-37422
10 Sep 2021 — Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. Zoho ManageEngine ADSelfService Plus versiones 6111 y anteriores, es vulnerable a una inyección SQL mientras se vinculan las bases de datos • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-37423
https://notcve.org/view.php?id=CVE-2021-37423
10 Sep 2021 — Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. Zoho ManageEngine ADSelfService Plus versiones 6111 y anteriores, son vulnerables a una toma de posesión de aplicaciones vinculadas • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release •

CVE-2021-37421
https://notcve.org/view.php?id=CVE-2021-37421
30 Aug 2021 — Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, son vulnerables a una evasión de la restricción de acceso al portal de administración. • https://blog.stmcyber.com/vulns/cve-2021-37421 • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2021-37417
https://notcve.org/view.php?id=CVE-2021-37417
30 Aug 2021 — Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, permiten omitir el CAPTCHA debido a una comprobación inapropiada de los parámetros. • https://blog.stmcyber.com/vulns/cve-2021-37417 • CWE-287: Improper Authentication •

CVE-2021-37416
https://notcve.org/view.php?id=CVE-2021-37416
30 Aug 2021 — Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, es vulnerable a un ataque de tipo XSS reflejado en la página loadframe. • https://blog.stmcyber.com/vulns/cve-2021-37416 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-33055
https://notcve.org/view.php?id=CVE-2021-33055
30 Aug 2021 — Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions. Zoho ManageEngine ADSelfService Plus versiones hasta 6102, permite una ejecución de código remota no autenticado en ediciones no Inglesas. • https://blog.stmcyber.com/vulns/cve-2021-33055 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2021-31874
https://notcve.org/view.php?id=CVE-2021-31874
02 Jul 2021 — Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync database application. Zoho ManageEngine ADSelfService Plus versiones anteriores a 6104, en raras situaciones, permite a atacantes obtener información confidencial sobre la aplicación de base de datos de sincronización de contraseñas • https://blog.stmcyber.com/vulns/cve-2021-31874 •

CVE-2021-27956
https://notcve.org/view.php?id=CVE-2021-27956
20 May 2021 — Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field. Zoho ManageEngine ADSelfService Plus versiones anteriores a 6104, permite un ataque de tipo XSS almacenado en la página de búsqueda de usuarios /webclient/index.html#/directory-search por medio del campo e-mail address • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6104-released-with-an-important-security-fixes • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-5353
https://notcve.org/view.php?id=CVE-2018-5353
29 Sep 2020 — The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the... • https://github.com/missing0x00/CVE-2018-5353 • CWE-290: Authentication Bypass by Spoofing •