Two-Factor Authentication Bypass in Zoho ManageEngine ADManager Plus
CVE-2023-41904
5.4MEDIUM
What is CVE-2023-41904?
A vulnerability in Zoho ManageEngine ADManager Plus prior to version 7203 allows attackers to bypass two-factor authentication during AuthToken generation in REST APIs. This exposes sensitive data and user accounts to unauthorized access, potentially compromising security measures intended to protect system integrity.