Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_adselfservice_plus | Zohocorp | 6.1-6121 (including) | 6.1-6121 (including) |