Security Advisories

Vulnerabilities identified by Horizon during security assessments and research activities

Immagine

ManageEngine ADSelfService Plus privilege escalation - CVE-2021-27214

Horizon Security discovered a Server-side request forgery (SSRF) vulnerability in ManageEngine AdSelfService Plus version 6013 and lower which allows an attacker to perform a privilege escalation attack.

Friday, 19 February 2021AutoreHorizon Security Staff