CVE-2021-33617
31.07.2021, 17:15
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_password_manager_pro | 𝑥 < 11.2 |
zohocorp | manageengine_password_manager_pro | 11.2 |
𝑥
= Vulnerable software versions
References