vendor:
Service Desk Plus
by:
Ata Hakçıl, Melih Kaan Yıldız
8.8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Service Desk Plus
Affected Version From: <10.0
Affected Version To: 10.0
Patch Exists: YES
Related CWE: CVE-2019-10008
CPE: a:manageengine:servicedesk_plus
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2019
Manage Engine ServiceDesk Plus Version <10.0 Privilege Escalation
Manage Engine ServiceDesk Plus Version <10.0 is vulnerable to privilege escalation. An attacker can bypass authentication and gain access to the system with high privileges by setting the JSESSIONID cookie.
Mitigation:
Upgrade to version 10.0.10017 or later.