CVE-2023-28342: Zohocorp ManageEngine Adselfservice Plus

High severity, CVSS 7.5. EPSS: 78.3% chance of exploitation in the next 30 days.

Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.

Affected products

  • Zohocorp ManageEngine Adselfservice Plus: version 4.5 only; version 5.0 only; version 5.0.6 only; version 5.1 only; version 5.2 only; version 5.3 only; …

Published 2023-04-05. Last modified 2026-06-17.