CVE-2018-7248: Medium severity ZohoCorp ManageEngine ServiceDesk Plus vulnerability
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7248?
CVE-2018-7248 is a vulnerability in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317 that allows unauthenticated users to validate domain user accounts and retrieve the user's logon domain.
How severe is CVE-2018-7248?
CVE-2018-7248 has a severity score of 5.3, which is classified as medium.
How can I exploit CVE-2018-7248?
To exploit CVE-2018-7248, an attacker can send a request containing a username to an API endpoint and retrieve the user's logon domain.
Is there a fix available for CVE-2018-7248?
At the time of writing, there is no known fix available for CVE-2018-7248. It is recommended to follow the vendor's advisory and apply any necessary patches or updates when they become available.
Where can I find more information about CVE-2018-7248?
You can find more information about CVE-2018-7248 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/104287), [GitLab](https://gitlab.com/e-sterling/cve-2018-7248), [Medium](https://medium.com/@esterling_/cve-2018-7248-enumerating-active-directory-users-via-unauthenticated-manageengine-servicedesk-a1eda2942eb0)