CVE-2010-3272: Input Validation
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) HideCaptcha or (2) quesList parameter in a validateAll action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3272?
The severity of CVE-2010-3272 is considered high due to its impact on user account security.
How do I fix CVE-2010-3272?
To fix CVE-2010-3272, upgrade ManageEngine ADSelfService Plus to version 4.5 Build 4500 or later.
What type of attacks does CVE-2010-3272 enable?
CVE-2010-3272 enables remote attackers to reset user passwords and potentially gain unauthorized access to user accounts.
Which versions of ManageEngine ADSelfService Plus are affected by CVE-2010-3272?
Versions of ManageEngine ADSelfService Plus prior to 4.5 Build 4500 are affected by CVE-2010-3272.
What is the primary vulnerability in CVE-2010-3272?
The primary vulnerability in CVE-2010-3272 lies in the insecure handling of security questions during the password reset process.