Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.
References
| Link | Resource |
|---|---|
| https://github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/admanager-recovery-password-disclosure.md | Exploit Third Party Advisory |
| https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-31492.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-08-17 23:15
Updated : 2023-08-23 18:09
NVD link : CVE-2023-31492
Mitre link : CVE-2023-31492
JSON object : View
Products Affected
zohocorp
- manageengine_admanager_plus
CWE
CWE-522
Insufficiently Protected Credentials
