6.8
CVSSv2

CVE-2014-9331

Published: 04/02/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central prior to 9 build 90130 allows remote malicious users to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine desktop central

Exploits

<html> <!-- # Exploit Title: ManageEngine Desktop Central 9 Add and admin user through Cross-Site Request Forgery (CSRF) # Date: 05 December 2014 # Exploit Author: Mohamed Idris – Help AG Middle East # Vendor Homepage: wwwmanageenginecom/ # Software Link: wwwmanageenginecom/products/desktop-central/ # Version: All versi ...