CVE-2019-18781: Zohocorp ManageEngine Adselfservice Plus

Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.

An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.

Affected products

  • Zohocorp ManageEngine Adselfservice Plus: version 5.0 only; version 5.1 only; version 5.2 only; version 5.3 only; version 5.4 only; version 5.5 only; …

Published 2019-12-18. Last modified 2026-06-17.