// For flags

CVE-2019-15083

ManageEngine Service Desk 10.0 - Cross-Site Scripting

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home > Server > <workstation> > software" the administrator of ManageEngine can control what software is installed on the workstation. This table shows all the installed program names in the Software column. In this field, a remote attacker can inject malicious code in order to execute it when the ManageEngine administrator visualizes this page.

Las instalaciones predeterminadas de Zoho ManageEngine ServiceDesk Plus versiones 10.0 anteriores a 10500, son vulnerables un ataque de tipo XSS inyectado por un administrador local de la estación de trabajo. Usando los nombres de los programas instalados de la computadora como un vector, el administrador local puede ejecutar el código en el lado del administrador de Manage Engine ServiceDesk. En "Asset Home ) Server ) (workstation) ) software" el administrador de ManageEngine puede controlar cual software está instalado en la estación de trabajo. Esta tabla muestra todos los nombres de los programas instalados en la columna Software. En este campo, un atacante remoto puede inyectar código malicioso para ejecutarlo cuando el administrador de ManageEngine visualice esta página.

ManageEngine Service Desk version 10.0 suffers from a cross site scripting vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-08-15 CVE Reserved
  • 2020-05-14 CVE Published
  • 2023-10-18 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
-
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10000
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10001
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10002
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10003
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10004
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10005
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10006
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10007
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10008
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10009
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10010
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10011
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10012
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10013
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10014
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10015
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10016
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10017
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10018
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10019
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10020
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
10.0.0
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "10.0.0"
10021
Affected