An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
References
Link | Resource |
---|---|
https://medium.com/@esterling_/cve-2018-7248-enumerating-active-directory-users-via-unauthenticated-manageengine-servicedesk-a1eda2942eb0 | Exploit Third Party Advisory |
https://gitlab.com/e-sterling/cve-2018-7248 | Exploit Third Party Advisory |
http://www.securityfocus.com/bid/104287 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-05-11 07:29
Updated : 2020-06-29 17:12
NVD link : CVE-2018-7248
Mitre link : CVE-2018-7248
JSON object : View
CWE
Products Affected
zohocorp
- manageengine_servicedesk_plus