CVE-2019-12476

MEDIUM

Zohocorp Manageengine Adselfservice Plus - Password Reset Weakness

Title source: rule
STIX 2.1

Description

An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input.

Exploits (1)

nomisec WORKING POC 44 stars
by 0katz · poc
https://github.com/0katz/CVE-2019-12476

Scores

CVSS v3 6.8
EPSS 0.0116
EPSS Percentile 78.7%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-640
Status published
Products (1)
zohocorp/manageengine_adselfservice_plus 4.3.3 - 5.0.6
Published Jun 17, 2019
Tracked Since Feb 18, 2026