CVE-2019-10273: Medium severity zohocorp manageengine servicedesk plus vulnerability
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10273?
CVE-2019-10273 is an information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software.
How does CVE-2019-10273 impact ManageEngine ServiceDesk Plus 9.3?
CVE-2019-10273 allows authenticated users to enumerate active users, potentially exposing sensitive information.
What is the severity of CVE-2019-10273?
CVE-2019-10273 has a severity rating of 4.3, which is considered medium.
How can an attacker exploit CVE-2019-10273?
An attacker can exploit CVE-2019-10273 by logging in to the /mc login page and verifying active accounts.
Is there a fix for CVE-2019-10273?
To fix CVE-2019-10273, it is recommended to apply the latest patch or upgrade to a newer version of ManageEngine ServiceDesk Plus.