CVE-2019-10008: High severity zoho manageengine servicedesk plus vulnerability
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10008?
CVE-2019-10008 has a high severity rating due to possible session hijacking and privilege escalation.
How do I fix CVE-2019-10008?
To fix CVE-2019-10008, update Zoho ManageEngine ServiceDesk to the latest version that addresses this vulnerability.
What kind of attack does CVE-2019-10008 allow?
CVE-2019-10008 allows attackers to hijack a guest session and escalate privileges to an administrator.
Which software versions are affected by CVE-2019-10008?
CVE-2019-10008 affects Zoho ManageEngine ServiceDesk version 9.3.
What is the impact of exploiting CVE-2019-10008?
Exploiting CVE-2019-10008 can lead to unauthorized access and changes to sensitive information, compromising system integrity.