CVE-2021-31159
MEDIUMZoho ManageEngine ServiceDesk Plus MSP <10519 - Info Disclosure
Title source: llmDescription
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
Exploits (2)
References (4)
Scores
CVSS v3
5.3
EPSS
0.2195
EPSS Percentile
95.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-209
Status
published
Products (1)
zohocorp/manageengine_servicedesk_plus_msp
10.5 10500 (50 CPE variants)
Published
Jun 16, 2021
Tracked Since
Feb 18, 2026