← back
CVE-2022-28987observed exploitation

CVE-2022-28987

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 10%
from disclosure to weapon
Published on NVDMay 20
VulnCheck+1412d
exploitation probability
10%top 5% of all CVEs
observed exploitation
yesVulnCheck
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.
Affected products
n/a · n/a