NA

CVE-2023-32783

Published: 07/08/2023 Updated: 11/04/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an malicious user to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine_adaudit_plus 7.1.1