CVE-2023-38332

EUVD-2023-42150
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_admanager_plus
𝑥
< 7.2
zohocorpmanageengine_admanager_plus
7.2:7200
zohocorpmanageengine_admanager_plus
7.2:7201
𝑥
= Vulnerable software versions