CVE-2023-31492

MEDIUM

Zoho ManageEngine ADManager Plus <7182 - Info Disclosure

Title source: llm
STIX 2.1

Description

Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 46.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (2)
zohocorp/manageengine_admanager_plus 7.1 (35 CPE variants)
zohocorp/manageengine_admanager_plus < 7.1
Published Aug 17, 2023
Tracked Since Feb 18, 2026