CVE-2025-1723

Published Mar 3, 2025

Last updated a month ago

Overview

Description
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
Source
0fc0942c-577d-436f-ae8e-945763c79b02
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity
HIGH

Weaknesses

0fc0942c-577d-436f-ae8e-945763c79b02
CWE-287

Social media

Hype score
Not currently trending
  1. ManageEngine ADSelfService Plus has a patched session hijacking vulnerability (CVE-2025-1723) affecting versions ≤ 6510. Patch now to prevent account takeovers, especially if MFA is disabled. Medium risk, high impact. Details: https://t.co/afC9zf5OOH #CVE-2025-1723

    @RedTeamNewsBlog

    24 Mar 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-1723 (CVSS:8.1, HIGH) is Undergoing Analysis. Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session m..https://t.co/CUshkuPtt9 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    8 Mar 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-1723 Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup o… https://t.co/VCSxCTUFKn

    @CVEnew

    7 Mar 2025

    175 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 A critical vulnerability (CVE-2025-1723) in Zoho ADSelfService Plus could allow unauthorized access if MFA is disabled. Update to version 6511 to secure sensitive data. 🇮🇳 #ZohoSecurity #MFAEnabled #InfoLeak link: https://t.co/p7A0OQRcjG https://t.co/BYmrhsOcHq

    @TweetThreatNews

    5 Mar 2025

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ Vulnerability Alert: Zoho ADSelfService Plus Account Takeover Vulnerability 📅 Timeline: Disclosure: 2025-03-03, Patch: 2025-02-26 📌 Attribution: Weston (Zoho BugBounty program) 🆔cveId: CVE-2025-1723 📊baseScore: 8.1 📏cvssMetrics: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N… htt

    @syedaquib77

    5 Mar 2025

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨Alert🚨 CVE-2025-1723: Zoho Patches Account Takeover Vulnerability in ADSelfService Plus 📊 13.1K+ Services are found on the https://t.co/ysWb28Crld yearly. 🔗Hunter Link:https://t.co/u8cYgWQkPG 👇Query HUNTER : https://t.co/q9rtuGgxk7="ManageEngine ADSelfService Plus" FOFA :…

    @HunterMapping

    5 Mar 2025

    345 Impressions

    1 Retweet

    1 Like

    2 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CVE-2025-1723 🔴 HIGH (8.1) 🏢 ManageEngine - ADSelfService Plus 🏗️ 0 🔗 https://t.co/MhWKLCTQuZ #CyberCron #VulnAlert #InfoSec https://t.co/RWqdoJmWDy

    @cybercronai

    4 Mar 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes