Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6463 | Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token. |
Mon, 17 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Mar 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token. | |
| Title | Account Takeover | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2025-03-17T14:38:10.240Z
Reserved: 2025-02-26T17:09:31.874Z
Link: CVE-2025-1724
Updated: 2025-03-17T14:38:04.275Z
Status : Deferred
Published: 2025-03-17T07:15:33.467
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-1724
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:25Z
EUVD