CVE-2019-12476
Published
CVSS v3
N/A
CVSS v2
7.2
HIGH
Affected
1
PROJECT
Description
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input.