Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-04-24T18:58:55

Updated: 2024-08-04T22:10:08.609Z

Reserved: 2019-03-24T00:00:00

Link: CVE-2019-10008

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-04-24T19:29:00.907

Modified: 2019-04-25T16:33:23.347

Link: CVE-2019-10008

cve-icon Redhat

No data.