Zoho ManageEngine ADSelfService Plus 5.x Cross-Site Request Forgery (CSRF) Vulnerability

Summary

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users’ profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. 

Credit:

The information has been provided by Pornsook Kornkitichai

The original article can be found at:https://gist.github.com/aliceicl/e32fb4a17277c7db9e0256185ac03dae

 


Details

Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.

 

Vulnerable Systems:

Zoho ManageEngine ADSelfService Plus 5.x 

 

CVE Information:

CVE-2019-18411

 

Disclosure Timeline:
Published Date:11/6/2019