Input validation error in Zoho ManageEngine ADSelfService Plus - #VU65902
Published: July 30, 2022
Vulnerability identifier: #VU65902
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in quick enrollment configuration when connecting to MySQL database. A remote privileged user can pass specially crafted input to the application and execute arbitrary code.
Affected software
Zoho ManageEngine ADSelfService Plus
Remediation
Install updates from vendor's website.
Zoho ManageEngine ADSelfService Plus - update to 6204