CVE-2021-31159

MEDIUM

Zoho ManageEngine ServiceDesk Plus MSP <10519 - Info Disclosure

Title source: llm

Description

Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

Exploits (2)

exploitdb WORKING POC
by Ricardo Ruiz · pythonwebappsjava
https://www.exploit-db.com/exploits/50027
nomisec WORKING POC 3 stars
by ricardojoserf · poc
https://github.com/ricardojoserf/CVE-2021-31159

Scores

CVSS v3 5.3
EPSS 0.2195
EPSS Percentile 95.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-209
Status published
Products (1)
zohocorp/manageengine_servicedesk_plus_msp 10.5 10500 (50 CPE variants)
Published Jun 16, 2021
Tracked Since Feb 18, 2026