vendor:
ManageEngine ADSelfService Plus
by:
Ibrahim Raafat
6.1
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: ManageEngine ADSelfService Plus
Affected Version From: 5.7
Affected Version To: 5702
Patch Exists: YES
Related CWE: CVE-2018-20484,CVE-2018-20485
CPE: a:zoho:manageengine_adselfservice_plus:5.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: All
2018
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Multiple Cross-Site Scripting
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has Multiple XSS vulnerabilites. The vulnerabilities can be exploited by sending malicious payloads to the Employee search form, Employee Search – ascending parameter, EmpSearch.cc - searchString parameter and Stored XSS in self-update layout implementation.
Mitigation:
The vendor has released a patch to address the issue.