PT-2011-1394 · Manageengine · Zoho Manageengine Adselfservice Plus

Ernesto Alvarez

·

Published

2011-02-17

·

Updated

2018-10-10

·

CVE-2010-3272

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine ADSelfService Plus versions prior to 4.5 Build 4500
Description The issue concerns the security-questions implementation in ManageEngine ADSelfService Plus, where the "accounts/ValidateAnswers" endpoint is vulnerable to password reset attacks. Remote attackers can exploit this by modifying the Hide Captcha or quesList parameter in a validateAll action, allowing them to reset user passwords and gain access to arbitrary user accounts.
Recommendations For versions prior to 4.5 Build 4500, update to version 4.5 Build 4500 or later to resolve the issue. As a temporary workaround, consider restricting access to the "accounts/ValidateAnswers" endpoint or disabling the security-questions feature until a patch is applied. Avoid using the Hide Captcha or quesList parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3272

Affected Products

Zoho Manageengine Adselfservice Plus