Authentication Bypass Vulnerability in Zoho ManageEngine SupportCenter Plus
CVE-2022-36412
9.8CRITICAL
What is CVE-2022-36412?
Zoho ManageEngine SupportCenter Plus prior to version 11023 is susceptible to an authentication bypass through V3 API requests. This vulnerability allows unauthorized execution of API requests using the credentials of previously authenticated users, potentially compromising sensitive information and system integrity. Immediate action should be taken to update to the latest version to mitigate risks associated with this flaw.