Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpc7-m273-pggq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

EPSS

Процентиль: 92%
0.09112
Низкий

8.8 High

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 8.8
nvd
почти 7 лет назад

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

EPSS

Процентиль: 92%
0.09112
Низкий

8.8 High

CVSS3

Дефекты

CWE-384