CVE-2021-31159
Description
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Zoho ManageEngine ServiceDesk Plus MSP before build 10519 allows user enumeration via distinct error messages in the Forgot Password functionality.
Vulnerability
Zoho ManageEngine ServiceDesk Plus MSP before build 10519 is vulnerable to a user enumeration bug in the Forgot Password functionality. The application returns different error messages depending on whether the provided username exists in the system. This improper error-message generation allows an attacker to determine valid user accounts. The issue is tracked as SDPMSP-15732 [1].
Exploitation
An attacker with network access to the Forgot Password page can exploit this vulnerability without authentication. By submitting password reset requests for a list of usernames, the attacker observes the response: if the user exists, the server returns a message indicating an email has been sent; if the user does not exist, a different message is returned. This behavior can be automated to enumerate accounts, including Active Directory users if AD authentication is enabled [4].
Impact
Successful exploitation allows an attacker to enumerate valid user accounts, including Active Directory users, which can be used to perform targeted attacks such as password spraying or social engineering. The vulnerability does not directly lead to privilege escalation or data disclosure, but it significantly reduces the attacker's reconnaissance effort.
Mitigation
The vulnerability is fixed in build 10519 of Zoho ManageEngine ServiceDesk Plus MSP [1]. Users should upgrade to this version or later. No workarounds are documented. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho ManageEngine/ServiceDesk Plus MSPdescription
- Range: <10519
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
3- packetstormsecurity.com/files/163192/Zoho-ManageEngine-ServiceDesk-Plus-9.4-User-Enumeration.htmlmitrex_refsource_MISC
- www.manageengine.commitrex_refsource_MISC
- www.manageengine.com/products/service-desk-msp/readme.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.