Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.manageengine.com/products/desktop-central/improper-access-control.html | vendor advisory |
https://www.manageengine.com/products/desktop-central/help/introduction/release_notes.html | release notes vendor advisory |