CVE Vulnerabilities

CVE-2022-26777

Direct Request ('Forced Browsing')

Published: Apr 16, 2022 | Modified: Aug 08, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Manageengine_remote_access_plus Zohocorp * 10.1.2137.15 (excluding)

Potential Mitigations

References