First published: Wed Jan 07 2015(Updated: )
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ADSelfService Plus before 5.2 Build 5202 allows remote attackers to inject arbitrary web script or HTML via the name parameter to GroupSubscription.do.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ADSelfService Plus | <=5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3779 has a high severity rating due to its potential for allowing arbitrary script injection through XSS.
To fix CVE-2014-3779, upgrade ManageEngine ADSelfService Plus to version 5.2 Build 5202 or later.
The impact of CVE-2014-3779 includes the possibility for attackers to execute arbitrary scripts in users' browsers.
Yes, CVE-2014-3779 is relatively easy to exploit, making it a significant risk for affected systems.
Workarounds for CVE-2014-3779 include validating and sanitizing user input in the application to prevent script injection.