CVE-2018-20485
MEDIUMManageEngine ADSelfService Plus 5.7 - Cross-Site Scripting in Employee Search Feature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-20485. PoCs published by Ibrahim Raafat.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in Zoho ManageEngine ADSelfService Plus. It includes payloads for reflected and stored XSS in various endpoints, such as EmployeeSearch.cc and SelfService.do, with specific injection points and payloads.
Description
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in Zoho ManageEngine ADSelfService Plus. It includes payloads for reflected and stored XSS in various endpoints, such as EmployeeSearch.cc and SelfService.do, with specific injection points and payloads.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N