VYPR
Unrated severityNVD Advisory· Published Jun 16, 2021· Updated Aug 3, 2024

CVE-2021-31159

CVE-2021-31159

Description

Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zoho ManageEngine ServiceDesk Plus MSP before build 10519 allows user enumeration via distinct error messages in the Forgot Password functionality.

Vulnerability

Zoho ManageEngine ServiceDesk Plus MSP before build 10519 is vulnerable to a user enumeration bug in the Forgot Password functionality. The application returns different error messages depending on whether the provided username exists in the system. This improper error-message generation allows an attacker to determine valid user accounts. The issue is tracked as SDPMSP-15732 [1].

Exploitation

An attacker with network access to the Forgot Password page can exploit this vulnerability without authentication. By submitting password reset requests for a list of usernames, the attacker observes the response: if the user exists, the server returns a message indicating an email has been sent; if the user does not exist, a different message is returned. This behavior can be automated to enumerate accounts, including Active Directory users if AD authentication is enabled [4].

Impact

Successful exploitation allows an attacker to enumerate valid user accounts, including Active Directory users, which can be used to perform targeted attacks such as password spraying or social engineering. The vulnerability does not directly lead to privilege escalation or data disclosure, but it significantly reduces the attacker's reconnaissance effort.

Mitigation

The vulnerability is fixed in build 10519 of Zoho ManageEngine ServiceDesk Plus MSP [1]. Users should upgrade to this version or later. No workarounds are documented. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.