CVE-2022-28987

Publication date

2022-05-20 02:10:39

Family

mitre

State

PUBLISHED

Description

Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.