CVE-2021-33256: Critical severity adselfservice plus vulnerability
DISPUTED A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The jusername parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side."
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33256?
CVE-2021-33256 is a CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version 6.1 Build No 6101.
What is the severity of CVE-2021-33256?
The severity of CVE-2021-33256 is critical with a CVSS score of 8.8.
How can an unauthenticated user exploit CVE-2021-33256?
An unauthenticated user can exploit CVE-2021-33256 by using the j_username parameter to inject a CSV payload.
What is the impact of CVE-2021-33256?
CVE-2021-33256 can allow an attacker to execute arbitrary commands or obtain a reverse shell on the affected system.
Is there a fix for CVE-2021-33256?
At the moment, there is no official fix or patch available for CVE-2021-33256. It is recommended to follow the mitigation steps provided by the vendor.