CVE-2022-24681
ManageEngine ADSelfService Plus <6121 - Stored Cross-Site Scripting
Record summary
CVE-2022-24681 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMManageEngine ADSelfService Plus <6121 - Stored Cross-Site ScriptingCVSS 6.1
ManageEngine ADSelfService Plus before 6121 contains a stored cross-site scripting vulnerability via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screens.
Impact
Successful exploitation of this vulnerability could lead to the execution of arbitrary scripts or theft of sensitive information.
Remediation
Upgrade to a version of ManageEngine ADSelfService Plus that is higher than 6121 to mitigate this vulnerability.
Source: ProjectDiscovery