CVE-2022-36412
26.07.2022, 14:15
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)Enginsight
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_supportcenter_plus | 11.0:11020 |
| zohocorp | manageengine_supportcenter_plus | 11.0:11021 |
| zohocorp | manageengine_supportcenter_plus | 11.0:11022 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration