Vulnerabilities > CVE-2019-12252 - Authorization Bypass Through User-Controlled Key vulnerability in Zohocorp Manageengine Servicedesk Plus

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
zohocorp
CWE-639
exploit available

Summary

In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.

Exploit-Db

idEDB-ID:46894
last seen2019-05-22
modified2019-05-22
published2019-05-22
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46894
titleZoho ManageEngine ServiceDesk Plus < 10.5 - Improper Access Restrictions

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/153029/zohomesdp-escalate.txt
idPACKETSTORM:153029
last seen2019-05-24
published2019-05-22
reporterEnter Of VinCSS
sourcehttps://packetstormsecurity.com/files/153029/Zoho-ManageEngine-ServiceDesk-Plus-Privilege-Escalation.html
titleZoho ManageEngine ServiceDesk Plus Privilege Escalation