.. / CVE-2022-24681

Exploit for ManageEngine ADSelfService Plus <6121 - Stored Cross-Site Scripting (CVE-2022-24681)

Description:

ManageEngine ADSelfService Plus before 6121 contains a stored cross-site scripting vulnerability via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screens.

Nuclei Template

View the template here CVE-2022-24681.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-24681.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-24681
https://raxis.com/blog/cve-2022-24681
https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-24681.html
https://www.manageengine.com/products/self-service-password/kb/CVE-2022-24681.html
https://manageengine.com