peter bassill · operator
$ cve CVE-2019-10008 JSON

CVE-2019-10008 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 19.4% (pctl 97)

Patch early

A public exploit exists.

Description

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS19.4% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-384
On CISA KEVno
Public exploityes
Published2019-04-24
Last modified2026-06-17

Affected (1)

VendorProduct
zohocorpservicedesk plus

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD