Vulnerabilities > CVE-2018-7248 - Unspecified vulnerability in Zohocorp Manageengine Servicedesk Plus 9.3

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
zohocorp

Summary

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.

Vulnerable Configurations

Part Description Count
Application
Zohocorp
1