Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://manageengine.com | product |
https://www.manageengine.com/products/self-service-password/advisory/CVE-2023-28342.html | vendor advisory |