Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 00:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Wed, 29 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2023-03-07'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-21T23:15:41.530Z

Reserved: 2022-04-08T00:00:00.000Z

Link: CVE-2022-28810

cve-icon Vulnrichment

Updated: 2024-08-03T06:03:52.963Z

cve-icon NVD

Status : Analyzed

Published: 2022-04-18T13:15:08.233

Modified: 2025-10-31T14:40:07.210

Link: CVE-2022-28810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.