Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

0Katz

#38274de 53,633
7.2CVSS total
Vulnerabilidades · 1
PT-2019-12812
7.2
2019-06-17
Zoho · Zoho Manageengine Adselfservice Plus · CVE-2019-12476
**Name of the Vulnerable Software and Affected Versions** Zoho ManageEngine ADSelfService Plus versions prior to 5.0.6 **Description** The issue concerns an authentication bypass vulnerability in the password reset functionality. This vulnerability can be exploited by an attacker with physical access to gain a shell with SYSTEM privileges. The attack involves using a long sequence of crafted keyboard input via the restricted thick client browser. **Recommendations** For versions prior to 5.0.6, update to version 5.0.6 or later to resolve the issue. As a temporary workaround, consider restricting physical access to the system to minimize the risk of exploitation.