CVE-2018-7248
Last modified
CVE-2018-7248 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. EPSS estimates a 6.43% chance of exploitation in the next 30 days.
Description
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Zohocorp | Manageengine Servicedesk Plus | 9.3 | 9317 |
References
- http://www.securityfocus.com/bid/104287Third Party Advisory, VDB Entry
- https://gitlab.com/e-sterling/cve-2018-7248Exploit, Third Party Advisory
- http://www.securityfocus.com/bid/104287Third Party Advisory, VDB Entry
- https://gitlab.com/e-sterling/cve-2018-7248Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7248?
How severe is CVE-2018-7248?
How do I fix CVE-2018-7248?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7242Vulnerable hash algorithms exists in Schneider Electric's Mo…
- CVE-2018-7243An authorization bypass vulnerability exists In Schneider El…
- CVE-2018-7244An information disclosure vulnerability exists In Schneider …
- CVE-2018-7245An improper authorization vulnerability exists In Schneider …
- CVE-2018-7246A cleartext transmission of sensitive information vulnerabil…
- CVE-2018-7247An issue was discovered in pixHtmlViewer in prog/htmlviewer.…
- CVE-2018-7249An issue was discovered in secdrv.sys as shipped in Microsof…
- CVE-2018-7250An issue was discovered in secdrv.sys as shipped in Microsof…
- CVE-2018-7251An issue was discovered in config/error.php in Anchor 0.12.3…
- CVE-2018-7253The ParseDsdiffHeaderConfig function of the cli/dsdiff.c fil…
- CVE-2018-7254The ParseCaffHeaderConfig function of the cli/caff.c file of…
- CVE-2018-7259The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320…
Are you affected by CVE-2018-7248?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
