Zoho ManageEngine ADSelfService Plus 5.x Cross-Site Request Forgery (CSRF) Vulnerability
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users’ profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally.
The information has been provided by Pornsook Kornkitichai
The original article can be found at:https://gist.github.com/aliceicl/e32fb4a17277c7db9e0256185ac03dae
Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
Zoho ManageEngine ADSelfService Plus 5.x