Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.manageengine.com | product vendor advisory |
https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release | patch vendor advisory |
https://blog.stmcyber.com/vulns/cve-2021-37420/ | third party advisory exploit |