CVE-2018-20484

Published: Dic 26, 2018 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2018-13038 Aliases: GSD-2018-20484
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,1
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none
MEDIUM 4,3
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: none
Integrity: partial
Availability: none

Description

AI Translation Available

Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0170
Percentile
0,8th
Updated

EPSS Score Trend (Last 90 Days)

79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stable
Common Consequences
Security Scopes Affected:
Access Control Confidentiality Integrity Availability
Potential Impacts:
Bypass Protection Mechanism Read Application Data Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies: AI/ML, Web Based, Web Server
View CWE Details
Exploit

Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build …

Cross-Site Scripting (XSS)

Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting

View Exploit Code →
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5508:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5605:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5309:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5105:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5606:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5109:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5603:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5107:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5311:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5317:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5112:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5300:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5521:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5326:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5400:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5505:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5110:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5504:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5040:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5518:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5517:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5032:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5318:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5205:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5520:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5313:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5304:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5203:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5306:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5315:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5502:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5322:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5115:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5600:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5602:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5207:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5104:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5041:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5113:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5601:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5303:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5202:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5700:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5200:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5503:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:4500:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5204:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5116:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5302:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5325:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5701:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5323:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5320:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5206:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5501:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5108:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5327:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5106:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5512:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5305:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5509:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5321:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5102:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5329:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5316:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5328:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5330:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5516:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5111:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5514:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5510:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5515:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5519:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5312:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5500:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5114:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5308:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5511:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5101:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5506:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5513:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5100:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5310:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5319:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5314:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5201:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5507:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5301:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5604:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5324:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5307:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Manageengine Adselfservice Plus by Zohocorp

cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.7:5103:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://packetstormsecurity.com/files/152793/Zoho-ManageEngine-ADSelfService-Plu…
https://www.manageengine.com/products/self-service-password/release-notes.html
http://packetstormsecurity.com/files/152793/Zoho-ManageEngine-ADSelfService-Plu…
https://www.manageengine.com/products/self-service-password/release-notes.html