ManageEngine ServiceDesk Plus Application Compromise
A valid username can be used as both username/password to login and compromise the application through the “/mc/” directory which is the ‘mobile client’ directory. This can be achieved ONLY if Active Directory/LDAP is being used. This flaw exists because of the lack of password randomization in the application version 9.0 when a user is entered into the application, thus the application assigns the password as the username. The flaw can then be exploited by logging into the application through the “/mc” directory and then backing out of the “/mc” directory by deleting it from the URL thus positioning you in the main application with the authority of the user you logged in as. (Help locating a valid username can come from another disclosed vulnerability in the application).