Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.exploit-db.com/exploits/46659 | Exploit Third Party Advisory VDB Entry | 
| https://www.manageengine.com/products/service-desk/readme.html | Release Notes Vendor Advisory | 
| https://www.exploit-db.com/exploits/46659 | Exploit Third Party Advisory VDB Entry | 
| https://www.manageengine.com/products/service-desk/readme.html | Release Notes Vendor Advisory | 
Configurations
                    History
                    21 Nov 2024, 04:18
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.exploit-db.com/exploits/46659 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.manageengine.com/products/service-desk/readme.html - Release Notes, Vendor Advisory | 
Information
                Published : 2019-04-24 19:29
Updated : 2024-11-21 04:18
NVD link : CVE-2019-10008
Mitre link : CVE-2019-10008
CVE.ORG link : CVE-2019-10008
JSON object : View
Products Affected
                zohocorp
- servicedesk_plus
CWE
                
                    
                        
                        CWE-384
                        
            Session Fixation
