CVE-2010-3273
17.02.2011, 18:00
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to accounts/ResetResult.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_adselfservice_plus | 𝑥 ≤ 4.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References