CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It may be remotely exploitable.
CVE
CVE-2010-3272
Severity
MEDIUM
CVSS
4.3
EPSS
4.02%
Original NVD Description
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.