vendor:
ServiceDesk Plus
by:
Felipe Molina (@felmoltor)
6.1
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: ServiceDesk Plus
Affected Version From: 10.0
Affected Version To: 10.0
Patch Exists: YES
Related CWE: CVE-2019-15083
CPE: 2.3:a:manageengine:servicedesk_plus:10.0:*:*:*:*:*:*:*
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
ManageEngine Service Desk 10.0 – Cross-Site Scripting
Default installations of ManageEngine ServiceDesk Plus 10.0 were found to be vulnerable to a XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute JavaScript cods in the context of the ManageEngine ServiceDesk Plus application.
Mitigation:
Upgrade to the latest version of ManageEngine ServiceDesk Plus 10.0.