PT-2021-19194 · Zoho · Zoho Manageengine Servicedesk Plus

Ricardojoserf

·

Published

2021-06-16

·

Updated

2021-07-09

·

CVE-2021-31159

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ServiceDesk Plus MSP versions prior to 10519
Description The issue is related to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality. This bug allows for the enumeration of users, potentially leading to further attacks.
Recommendations For versions prior to 10519, update to version 10519 or later to resolve the issue. As a temporary workaround, consider restricting access to the Forgot Password functionality until a patch is applied.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31159

Affected Products

Zoho Manageengine Servicedesk Plus