/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_admanager_plus | - | 6.6 |
| zohocorp / manageengine_admanager_plus | 6.6-6601 | 6.6-6601.x |
| zohocorp / manageengine_admanager_plus | 6.6-6602 | 6.6-6602.x |
| zohocorp / manageengine_admanager_plus | 6.6-6610 | 6.6-6610.x |
| zohocorp / manageengine_admanager_plus | 6.6-6611 | 6.6-6611.x |
| zohocorp / manageengine_admanager_plus | 6.6-6612 | 6.6-6612.x |
| zohocorp / manageengine_admanager_plus | 6.6-6613 | 6.6-6613.x |