CVE-2017-17552: Zohocorp ManageEngine Admanager Plus

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.

Affected products

  • Zohocorp ManageEngine Admanager Plus: before 6.6 (fixed in 6.6); version 6.6 only

Published 2018-02-07. Last modified 2026-06-17.