CVE-2019-12476
17.06.2019, 18:15
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_adselfservice_plus | 4.3.3 ≤ 𝑥 < 5.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration