vendor:
ADSelfService Plus
by:
Metin Yunus Kandemir
8.8
CVSS
HIGH
CSV Injection
564
CWE
Product Name: ADSelfService Plus
Affected Version From: 6.1
Affected Version To: 6.1
Patch Exists: NO
Related CWE: N/A
CPE: a:manageengine:adselfservice_plus:6.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2021
ManageEngine ADSelfService Plus 6.1 – CSV Injection
ManageEngine ADSelfService Plus 6.1 is vulnerable to CSV Injection. A malicious user can send a POST request to the login page with a malicious payload in the j_username parameter. This payload will be saved to the User Attempts Audit Report table, which can be exported as a CSV file. If the admin user confirms the alert popup, a reverse shell connection will be obtained by the malicious user.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in a CSV file.