Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 07:45:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
Title Account takeover
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ManageEngine

Published: 2025-03-03T07:40:10.789Z

Updated: 2025-03-03T14:24:12.072Z

Reserved: 2025-02-26T17:07:32.710Z

Link: CVE-2025-1723

cve-icon Vulnrichment

Updated: 2025-03-03T14:24:06.686Z

cve-icon NVD

Status : Received

Published: 2025-03-03T08:15:15.717

Modified: 2025-03-03T08:15:15.717

Link: CVE-2025-1723

cve-icon Redhat

No data.