CVE-2019-12476
PoC —CVSS 3.0
6.8 medium
EPSS
2%p73
Published
()
Modified
Description
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input.
- Vendors
- zohocorp
- Products
- manageengine adselfservice plus
- Weakness
- CWE-640
- Vector
- CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.