A CSV injection vulnerability on the login panel of...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 30, 2024
Description
Published by the National Vulnerability Database
Aug 9, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Mar 30, 2024
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file.
References