CVE-2021-37417: Critical severity ZohoCorp ManageEngine ADSelfService Plus vulnerability
Published Aug 30, 2021
·Updated
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
Affected Software
6 affected components
ZohoCorp ManageEngine ADSelfService Plus<6.1
ZohoCorp ManageEngine ADSelfService Plus=6.1
ZohoCorp ManageEngine ADSelfService Plus=6.1-6100
ZohoCorp ManageEngine ADSelfService Plus=6.1-6101
ZohoCorp ManageEngine ADSelfService Plus=6.1-6102
ZohoCorp ManageEngine ADSelfService Plus=6.1-6103
Event History
Aug 30, 2021
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37417?
CVE-2021-37417 is a vulnerability in Zoho ManageEngine ADSelfService Plus version 6103 and prior that allows CAPTCHA bypass due to improper parameter validation.
2
What is the severity of CVE-2021-37417?
The severity of CVE-2021-37417 is critical with a CVSS score of 9.8.
3
How does CVE-2021-37417 affect Zoho ManageEngine ADSelfService Plus?
CVE-2021-37417 affects Zoho ManageEngine ADSelfService Plus version 6103 and prior, allowing CAPTCHA bypass due to improper parameter validation.
4
What is the fix for CVE-2021-37417?
To fix CVE-2021-37417, upgrade to a version of Zoho ManageEngine ADSelfService Plus that is not affected by the vulnerability.
5
Where can I find more information about CVE-2021-37417?
More information about CVE-2021-37417 can be found at the following reference: https://blog.stmcyber.com/vulns/cve-2021-37417/