Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-18411

Description

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.

POC

Reference

- https://gist.github.com/aliceicl/e32fb4a17277c7db9e0256185ac03dae

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/cyb3r-w0lf/nuclei-template-collection