|
ManageEngine ADSelfService Plus contains a flaw related to the security question verification mechanism. This may allow a remote attacker to eliminate the captcha verification and reduce the required number of questions to one, making it possible to brute force the answer to the question and change an arbitrary user's password.
|