A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T20:40:47.379Z
Reserved: 2021-02-14T00:00:00
Link: CVE-2021-27214
No data.
Status : Modified
Published: 2021-02-19T19:15:12.567
Modified: 2024-11-21T05:57:36.590
Link: CVE-2021-27214
No data.
OpenCVE Enrichment
No data.