Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10008

Опубликовано: 24 апр. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zohocorp:servicedesk_plus:9.3:*:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.09112
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

EPSS

Процентиль: 92%
0.09112
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-384