header-logo
Suggest Exploit
vendor:
ServiceDesk Plus
by:
Enter of VinCSS (Vingroup)
6.5
CVSS
MEDIUM
Incorrect Access Control
287
CWE
Product Name: ServiceDesk Plus
Affected Version From: < 10.5
Affected Version To: < 10.5
Patch Exists: YES
Related CWE: CVE-2019-12252
CPE: a:manageengine:servicedesk_plus
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: None
2019

Zoho ManageEngine ServiceDesk Plus < 10.5 Incorrect Access Control

In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.

Mitigation:

Ensure that access control policies are properly enforced and that users with the lowest privileges are not able to view arbitrary posts.
Source

Exploit-DB raw data:

# Exploit Title: Zoho ManageEngine ServiceDesk Plus < 10.5 Incorrect Access Control
# Date: 2019-05-21
# Exploit Author: Enter of VinCSS (Vingroup)
# Vendor Homepage: https://www.manageengine.com/products/service-desk
# Version: Zoho ManageEngine ServiceDesk Plus < 10.5
# CVE : CVE-2019-12252



In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the 

SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring