CVE-2019-10008
Summary
| CVE | CVE-2019-10008 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-24 19:29:00 UTC |
| Updated | 2019-04-25 16:33:00 UTC |
| Description | Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab. |
Risk And Classification
Problem Types: CWE-384
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zohocorp | Servicedesk Plus | 9.3 | All | All | All |
| Application | Zohocorp | Servicedesk Plus | 9.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.manageengine.com/products/service-desk/readme.html | CONFIRM | www.manageengine.com | Release Notes, Vendor Advisory |
| Manage Engine ServiceDesk Plus 10.0 - Privilege Escalation - JSP webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.