Files
CVEs-PoC/2018/CVE-2018-7248.md
T
2025-09-29 21:09:30 +02:00

945 B

CVE-2018-7248

Description

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.

POC

Reference

Github