CVE-2023-31492

MEDIUM

Zoho ManageEngine ADManager Plus <7182 - Info Disclosure

Title source: llm

Description

Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.

Scores

CVSS v3 6.5
EPSS 0.0030
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (36)

zohocorp/manageengine_admanager_plus < 7.1
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
zohocorp/manageengine_admanager_plus
... and 21 more

Timeline

Published Aug 17, 2023
Tracked Since Feb 18, 2026