Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.manageengine.com/products/support-center/cve-2022-42903.html | vendor advisory |