S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-24681 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Zoho ManageEngine ADSelfService Plus affects v. before 6121.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-24681
6.1
CVSS

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Zoho ManageEngine ADSelfService Plus is a comprehensive self-service password management and single sign-on solution used by businesses and organizations to improve security and productivity. This software facilitates end-users to reset passwords, unlock accounts, and change passwords on their own, without relying on IT support. Plus, it offers multifactor authentication support to add an extra layer of security to the access management process. ADSelfService Plus is widely recognized for its efficiency, ease of use, and extensive range of secure configurations.

The vulnerability code CVE-2022-24681 was detected in Zoho ManageEngine ADSelfService Plus before 6121 versions. This security flaw allowed cross-site scripting (XSS) through the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen. This XSS attack could be executed when a hacker creates a malicious link that when clicked would inject harmful code into the web page, leading to unauthorized access to sensitive data and confidential information.

If left unaddressed, this vulnerability could lead to severe repercussions for a business. For instance, an attacker could gain access to administrative credentials or steal sensitive data, leading to reputational damage, financial loss, and legal consequences. Furthermore, a successful XSS attack could also spread malware across the organization's network, potentially compromising all connected devices and systems.

s4e.io provides access to an extensive knowledgebase on data security and privacy threats and vulnerabilities, including those affecting Zoho ManageEngine ADSelfService Plus. This website's pro features allow users to receive real-time notifications of security vulnerabilities, as well as implementing a proactive monitoring approach. With s4e.io, organizations can stay ahead of the curve in terms of cyber threats, safeguarding their digital assets, and preserving business continuity.

 

REFERENCES

Solution Advice

Organizations using Zoho ManageEngine ADSelfService Plus can take several precautions to safeguard against this vulnerability. These include:

  • Regularly updating the software to the latest version.
  • Finding and fixing any software security vulnerabilities.
  • Implementing robust access control policies and multifactor authentication mechanisms.
  • Training employees on how to identify and avoid suspicious emails, links, and attachments.
  • Conducting regular security audits and penetration testing.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.