Medium severity5.4NVD Advisory· Published Sep 27, 2023· Updated Jun 17, 2026
CVE-2023-41904
CVE-2023-41904
Description
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6<7203+ 1 more
- (no CPE)range: <7203
- (no CPE)
cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*range: <7.2
- cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.2:7200:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.2:7201:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.2:7202:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.