ManageEngine ServiceDesk 8.0 – Multiple Vulnerabilities
Multiple persistent input validation vulnerabilities are detected in ManageEngines ServiceDesk v8.0 Plus web application. The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent). Two vulnerabilities are located in the my details and request new incidents module of the web front-end with the bound vulnerable name, subject and description parameters. Exploitation requires low user inter action & low privileged customer web application user account. The secound part of the bugs are located in the New Contract, Access points and Create Solution module of the admin/moderator back-end with the bound vulnerable title, asset name, contract name, description or support name. Successful exploitation of the vulnerability can lead to session hijacking (customer/manage) or stable (persistent) context manipulation. Exploitation of the persistent vulnerabilities results in account steal, persistent phishing attacks, persistent external redirects and persistent manipulation of affected or connected module context.