User Enumeration Vulnerability in Zoho ManageEngine ServiceDesk Plus MSP
CVE-2021-31159
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 16 June 2021
Badges
What is CVE-2021-31159?
The ManageEngine ServiceDesk Plus MSP application prior to version 10519 is susceptible to a user enumeration issue. This vulnerability arises from inadequate error message management during the password recovery process. As a result, attackers can exploit this flaw to determine whether an email address is registered in the system, potentially leading to unauthorized access attempts. Proper mitigation and updates are essential to safeguard the application against potential exploitation.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
23% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
- 🟡
Public PoC available
- 👾
Exploit known to exist