vendor:
ADSelfService Plus
by:
Bhadresh Patel
9.8
CVSS
CRITICAL
Unauthenticated Remote Code Execution
78
CWE
Product Name: ADSelfService Plus
Affected Version From: ADSelfService Plus build < 6003
Affected Version To: ADSelfService Plus build < 6003
Patch Exists: YES
Related CWE: CVE-2020-11552
CPE: a:manageengine:adselfservice_plus
Platforms Tested: Windows, Linux, Mac
2020
ManageEngine ADSelfService Plus Unauthenticated Remote Code Execution Vulnerability
A vulnerability in ManageEngine ADSelfService Plus could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists due to insufficient validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted system. A successful exploit could allow the attacker to execute arbitrary code on the system with the privileges of the web server process.
Mitigation:
ManageEngine has released a patch to address this vulnerability.