← Back

Manageengine Adselfservice Plus

manageengine_adselfservice_plus

Vendor: Zohocorp • 51 CVEs

CVEs (51)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Apr 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jan 3, 2019
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
1Zohocorp
1Manageengine Adselfservice Plus
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.
1Zohocorp
1Manageengine Adselfservice Plus
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
1Zohocorp
1Manageengine Adselfservice Plus
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
1Zohocorp
1Manageengine Adselfservice Plus
May 6, 2026
Jan 7, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ADSelfService Plus before 5.2 Build 5202 allows remote attackers to inject arbitrary web script or HTML via the name parameter to GroupSubscription.do.
1Zohocorp
1Manageengine Adselfservice Plus
Apr 29, 2026
Aug 23, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2)...Show more
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2) searchString parameters, a different vulnerability than CVE-2010-3274.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Apr 29, 2026
Feb 17, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script o...Show more
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString parameter in a (1) showList or (2) Search action.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Apr 29, 2026
Feb 17, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and...Show more
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to accounts/ResetResult.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Apr 29, 2026
Feb 17, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access...Show more
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.Show less