CVE-2021-31159
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 18%
from disclosure to weapon0 days
Published on NVDJun 16
1st PoCMar 19
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/50027unverifiedgithubgithub.com/ricardojoserf/CVE-2021-31159★ 3cve_referencepacketstormsecurity.com/files/163192/Zoho-ManageEngine-ServiceDesk-Plus-9.4-User-Enumeration.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.