Description
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
Published: 2018-02-07
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-8712 /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
History

Fri, 24 Oct 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Zohocorp
Zohocorp manageengine Admanager Plus
CPEs cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.6:6601:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.6:6602:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.6:6610:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.6:6611:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.6:6612:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.6:6613:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Admanager Plus
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 23 Oct 2025 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Admanager Plus

Subscriptions

Zohocorp Manageengine Admanager Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T20:51:32.285Z

Reserved: 2017-12-11T00:00:00.000Z

Link: CVE-2017-17552

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-02-07T17:29:01.183

Modified: 2025-10-24T15:47:02.450

Link: CVE-2017-17552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses