Security Advisory
CVE-2015-2560
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.