Vulnerabilities
Vulnerable Software
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
CVSS Score
6.1
EPSS Score
0.049
Published
2019-04-25
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.
CVSS Score
7.5
EPSS Score
0.026
Published
2019-03-21
Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.
CVSS Score
9.8
EPSS Score
0.014
Published
2019-01-03
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
CVSS Score
10.0
EPSS Score
0.012
Published
2019-01-03
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
CVSS Score
6.1
EPSS Score
0.006
Published
2018-12-26
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
CVSS Score
6.1
EPSS Score
0.006
Published
2018-12-26


Contact Us

Shodan ® - All rights reserved