First published: Mon Apr 18 2022(Updated: )
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Adselfservice Plus | <6.1 | |
Zohocorp Manageengine Adselfservice Plus | =6.1 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6100 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6101 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6102 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6103 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6104 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6105 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6106 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6107 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6108 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6109 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6110 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6111 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6112 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6113 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6114 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6115 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6116 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6117 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6118 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6119 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6120 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6121 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2022-28810.
The title of this vulnerability is Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability.
The severity of CVE-2022-28810 is high with a severity value of 6.8.
Zoho ManageEngine ADSelfService Plus versions 6.1 to 6.1-6121 are affected by CVE-2022-28810.
CVE-2022-28810 can be exploited by a remote authenticated administrator to execute arbitrary OS commands as SYSTEM via the policy custom script feature.