CVE-2019-10008
Manage Engine ServiceDesk Plus 10.0 - Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
Zoho ManageEngine ServiceDesk versión 9.3 permite el secuestro de sesión y la escalada de privilegios porque una sesión de invitado establecida se convierte automáticamente en una sesión de administrador establecida cuando el usuario invitado ingresa el nombre de usuario del administrador, con un contraseña incorrecta arbitraria, en un intento mc/login dentro de una pestaña diferente del navegador.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-03-24 CVE Reserved
- 2019-04-24 CVE Published
- 2019-08-17 First Exploit
- 2024-06-10 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-384: Session Fixation
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/46659 | 2024-08-04 | |
https://github.com/ignis-sec/CVE-2019-10008 | 2019-08-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.manageengine.com/products/service-desk/readme.html | 2019-04-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Servicedesk Plus Search vendor "Zohocorp" for product "Servicedesk Plus" | 9.3 Search vendor "Zohocorp" for product "Servicedesk Plus" and version "9.3" | - |
Affected
|