4.3
CVSSv3

CVE-2019-10273

Published: 04/04/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine servicedesk plus 9.3

Exploits

# Exploit Title: ManageEngine ServiceDesk Plus - 93 User enumeration vulnerability # Date: /03/29/2019 # Exploit Author: Alexander Bluestein # Vendor Homepage: wwwmanageenginecom/ # Software Link: wwwmanageenginecom/products/service-desk/downloadhtml # Version: 93 # Tested on: Ubuntu Linux # CVE : CVE-2019-10273 ManageEngin ...
ManageEngine ServiceDesk Plus version 93 suffers from a user enumeration vulnerability ...