Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/177091/ManageEngine-ADManager-Plus-Recovery-Password-Disclosure.html - | |
References | () https://github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/admanager-recovery-password-disclosure.md - Exploit, Third Party Advisory | |
References | () https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-31492.html - Vendor Advisory |
13 Feb 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary |
|
Information
Published : 2023-08-17 23:15
Updated : 2024-11-21 08:01
NVD link : CVE-2023-31492
Mitre link : CVE-2023-31492
CVE.ORG link : CVE-2023-31492
JSON object : View
Products Affected
zohocorp
- manageengine_admanager_plus
CWE
CWE-522
Insufficiently Protected Credentials