ManageEngine ADManager Plus versions prior to build 7181 are vulnerable to an authenticated command injection vulnerability due to insufficient validation of user input when performing the ChangePasswordAction function before passing it into a string that is later used as an OS command to execute.
b012514570e1f62ac98660fc2a609bf47f1a2401018b3b718ba15c2ec88e1b20