CVE-2010-3272
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via…
Does this matter?
Lower severity and a low EPSS score (4.02%). Track it; it rarely justifies an emergency change on its own.
Description
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 4.02% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- zohocorp/manageengine adselfservice plus
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/43241Vendor Advisory
- http://securityreason.com/securityalert/8089
- http://www.coresecurity.com/content/zoho-manageengine-vulnerabilitiesExploit
- http://www.osvdb.org/70870
- http://www.securityfocus.com/archive/1/516396/100/0/threaded
- http://www.securityfocus.com/bid/46331Exploit
- http://www.vupen.com/english/advisories/2011/0392Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65350
- http://secunia.com/advisories/43241Vendor Advisory
- http://securityreason.com/securityalert/8089
- http://www.coresecurity.com/content/zoho-manageengine-vulnerabilitiesExploit
- http://www.osvdb.org/70870
- http://www.securityfocus.com/archive/1/516396/100/0/threaded
- http://www.securityfocus.com/bid/46331Exploit
- http://www.vupen.com/english/advisories/2011/0392Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65350
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.