CVE-2021-37420
https://notcve.org/view.php?id=CVE-2021-37420
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing. Zoho ManageEngine ADSelfService Plus versiones anteriores a 6112, es vulnerable a una suplantación de correo • https://blog.stmcyber.com/vulns/cve-2021-37420 https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release https://www.manageengine.com • CWE-306: Missing Authentication for Critical Function •
CVE-2021-37424
https://notcve.org/view.php?id=CVE-2021-37424
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. ManageEngine ADSelfService Plus versiones anteriores a 6112, es vulnerable a una toma de control de cuentas de usuario de dominio • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release https://www.manageengine.com •
CVE-2021-33911
https://notcve.org/view.php?id=CVE-2021-33911
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution. Zoho ManageEngine ADManager Plus versiones anteriores a 7110, permite una ejecución de código remota • https://www.manageengine.com/products/ad-manager/release-notes.html#7110 •
CVE-2021-36771
https://notcve.org/view.php?id=CVE-2021-36771
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS. Zoho ManageEngine ADManager Plus versiones anteriores a 7110, permite un ataque de tipo XSS reflejado • https://www.manageengine.com/products/ad-manager/release-notes.html#7110 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-36772
https://notcve.org/view.php?id=CVE-2021-36772
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS. Zoho ManageEngine ADManager Plus versiones anteriores a 7110, permite un ataque de tipo XSS almacenado • https://www.manageengine.com/products/ad-manager/release-notes.html#7110 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •