CVE-2022-28810: ManageEngine ADSelfService Plus Authenticated Command Execution (Fixed)
CVE-2022-28810: ManageEngine ADSelfService Plus Authenticated Command Execution (Fixed) https://ift.tt/2zlAxGL On April 9, 2022, ManageEngine fixed CVE-2022-28810 with the release of ADSelfService Plus Build 6122. The vulnerability allowed the admin user to execute arbitrary operating system commands and potentially allowed partially authenticated Active Directory users to execute arbitrary operating system commands via the password reset functionality. […]