An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://www.manageengine.com/products/self-service-password/release-notes.html | release notes vendor advisory |
https://pitstop.manageengine.com/portal/community/topic/adselfservice-plus-5809-release | vendor advisory |