Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
Any version before 6401
affected
Description
Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.
Problem types
CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
Product status
Any version before 6401
References
www.manageengine.com/...assword/advisory/CVE-2024-27310.html
www.manageengine.com/...assword/advisory/CVE-2024-27310.html