Record summary

CVE-2022-24681 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMManageEngine ADSelfService Plus <6121 - Stored Cross-Site ScriptingCVSS 6.1

ManageEngine ADSelfService Plus before 6121 contains a stored cross-site scripting vulnerability via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screens.

Impact

Successful exploitation of this vulnerability could lead to the execution of arbitrary scripts or theft of sensitive information.

Remediation

Upgrade to a version of ManageEngine ADSelfService Plus that is higher than 6121 to mitigate this vulnerability.

WeaknessesCWE-79
AuthorsOpen-Sec
Template tagscvecve2022manageenginexssauthenticatedzohocorppassivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*
Shodan: http.title:"manageengine"
Shodan: http.title:"adselfservice plus"
FOFA: title="manageengine"
FOFA: title="adselfservice plus"
Google: intitle:"adselfservice plus"
Google: intitle:"manageengine"

Source: ProjectDiscovery

References

4