#VU25643 Improper access control in Zoho ManageEngine EventLog Analyzer - CVE-2019-19774
Published: February 27, 2020 / Updated: June 17, 2021
Zoho ManageEngine EventLog Analyzer
Zoho Corporation
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions by running "select hostdetails from hostdetails" at the /event/runquery.do
endpoint and recover the MD5 hashes of the accounts used to
authenticate the ManageEngine platform to the managed machines on the
network (most often administrative accounts).