ZeroHour

CVE-2022-36412

CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)

Vendors
zohocorp
Products
manageengine supportcenter plus
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.