vulnerability

Zoho ManageEngine ADSelfService Plus: CVE-2022-24681: Stored XSS

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Mar 3, 2022
Added
Dec 18, 2024
Modified
Jul 2, 2025

Description

An admin only Stored XSS vulnerability affects ADSelfService Plus via the reset password and unlock account operations.

Solution

zoho-manageengine-adselfservice-plus-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.