296,278
Total vulnerabilities in the database
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to accounts/ResetResult.
Software | From | Fixed in |
---|---|---|
zohocorp / manageengine_adselfservice_plus | - | 4.4.x |