vendor:
ServiceDesk Plus
by:
Muhammad Ahmed Siddiqui
3.3
CVSS
LOW
Improper Privilege Management
264
CWE
Product Name: ServiceDesk Plus
Affected Version From: 9
Affected Version To: 9.0 Build 9031
Patch Exists: YES
Related CWE: N/A
CPE: a:manageengine:servicedesk_plus
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
ManageEngine ServiceDesk Plus User Privileges Management Vulnerability
A user with limited privileges could gain access to certain functionality that is available only to administrative users. For example, users with Guest privileges can see the subjects of the tickets, stats and other information related to tickets.
Mitigation:
Ensure that users with limited privileges are not able to access application data.