vendor:
ServiceDesk Plus
by:
Narendra Shinde
7.5
CVSS
HIGH
Improper Privilege Management
269
CWE
Product Name: ServiceDesk Plus
Affected Version From: 8.0.0 Build 8013
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: a:manageengine:servicedesk_plus
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2011
ManageEngine ServiceDesk Plus Improper User Privileges Management Vulnerability
A user with limited privileges could gain access to certain functionality that is available only to administrative users. For example, users with Guest privileges could delete backup database from thier account.
Mitigation:
ManageEngine has released a patch to address this vulnerability.