Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 29 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2023-03-07'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-07-30T01:37:43.563Z

Reserved: 2022-04-08T00:00:00.000Z

Link: CVE-2022-28810

cve-icon Vulnrichment

Updated: 2024-08-03T06:03:52.963Z

cve-icon NVD

Status : Analyzed

Published: 2022-04-18T13:15:08.233

Modified: 2025-03-27T13:58:07.507

Link: CVE-2022-28810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.