CVE-2019-10008
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 19.39% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-384
- Affected
- zohocorp/servicedesk plus
- Source
- cve@mitre.org
References
- https://www.exploit-db.com/exploits/46659Exploit, Third Party Advisory, VDB Entry
- https://www.manageengine.com/products/service-desk/readme.htmlRelease Notes, Vendor Advisory
- https://www.exploit-db.com/exploits/46659Exploit, Third Party Advisory, VDB Entry
- https://www.manageengine.com/products/service-desk/readme.htmlRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.