CVE-2024-9097

EUVD-2024-50425
ManageEngine Endpoint Central versions beforeĀ 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.5 LOW
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
ManageEngineCNA
3.5 LOW
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_endpoint_central
11.3.2428.01 ≤
𝑥
< 11.3.2428.26
𝑥
= Vulnerable software versions