In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
2022-07-26T14:15:09.297
2024-11-21T07:12:57.710
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zohocorp | manageengine_supportcenter_plus | 11.0 | Yes |
Application | zohocorp | manageengine_supportcenter_plus | 11.0 | Yes |
Application | zohocorp | manageengine_supportcenter_plus | 11.0 | Yes |