← back
CVE-2022-24681

CVE-2022-24681

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 3.6%
exploitation probability
3.6%top 11% of all CVEs
observed exploitation
nono source reports it
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
Affected products
n/a · n/a