Zoho ManageEngine ADSelfService Plus through 6113 has an...
Critical severity
Unreviewed
Published
Jun 20, 2023
to the GitHub Advisory Database
•
Updated Mar 30, 2024
Description
Published by the National Vulnerability Database
Jun 20, 2023
Published to the GitHub Advisory Database
Jun 20, 2023
Last updated
Mar 30, 2024
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator.
References