CVE-2022-26653

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
16/04/2022
Last modified:
08/08/2023

Description

Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_remote_access_plus:*:*:*:*:*:*:*:* 10.1.2137.15 (excluding)