← Back to CVE List

CVE-2018-7248

Published: 2018-05-11T14:29Z
Last Modified: 2024-11-21T04:11Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt