VulnerabilityModified
CVE-2019-12252
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring.
MEDIUM 6.5EPSS 8.21%
Does this matter?
Lower severity and a low EPSS score (8.21%). Track it; it rarely justifies an emergency change on its own.
Description
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 8.21% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- zohocorp/manageengine servicedesk plus
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/153029/Zoho-ManageEngine-ServiceDesk-Plus-Privilege-Escalation.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108456Broken Link
- https://github.com/tuyenhva/CVE-2019-12252Third Party Advisory
- https://www.manageengine.com/products/service-desk/readme.htmlRelease Notes
- http://packetstormsecurity.com/files/153029/Zoho-ManageEngine-ServiceDesk-Plus-Privilege-Escalation.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108456Broken Link
- https://github.com/tuyenhva/CVE-2019-12252Third Party Advisory
- https://www.manageengine.com/products/service-desk/readme.htmlRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.