CVE-2019-18411

CVE-2019-18411

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users’ profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.

Source: CVE-2019-18411

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다