CVE Vulnerabilities

CVE-2018-7248

Published: May 11, 2018 | Modified: Nov 07, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the users logon domain if the accounts exists, or null if it does not.

Affected Software

Name Vendor Start Version End Version
Manageengine_servicedesk_plus Zohocorp 9.3-9317 (including) 9.3-9317 (including)

References