Vulnerability CVE-2021-33617


Published: 2021-07-31

Description:
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.

 References:
https://www.manageengine.com/products/passwordmanagerpro/release-notes.html#pmp11200
https://herolab.usd.de/security-advisories/usd-2021-0015/
https://www.manageengine.com

Copyright 2024, cxsecurity.com

 

Back to Top