CVE-2018-15608

MEDIUM

ManageEngine ADManager Plus 6.5.7 - HTML Injection in AD Delegation Help Desk Technicians Screen

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-15608. PoCs published by Ismail Tasdelen.

AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in ManageEngine ADManager Plus 6.5.7. The vulnerability allows an attacker to inject arbitrary HTML code into the 'AD Delegation' 'Help Desk Technicians' screen via the 'searchText' parameter.

Description

Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.

Exploits (1)

exploitdb WORKING POC
by Ismail Tasdelen · textwebappswindows
https://www.exploit-db.com/exploits/45254

This exploit demonstrates an HTML injection vulnerability in ManageEngine ADManager Plus 6.5.7. The vulnerability allows an attacker to inject arbitrary HTML code into the 'AD Delegation' 'Help Desk Technicians' screen via the 'searchText' parameter.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: ManageEngine ADManager Plus 6.5.7
Auth required
Prerequisites: Access to the application with valid credentials · Network access to the target server
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45254/

Scores

CVSS v3 6.1
EPSS 0.0247
EPSS Percentile 82.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
manageengine/admanager_plus 6.5.7
Published Aug 28, 2018
Tracked Since Feb 18, 2026