CVE-2019-10008 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 19.4% (pctl 97)
Patch early
A public exploit exists.
Description
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 19.4% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-384 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-24 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| zohocorp | servicedesk plus |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Manage Engine ServiceDesk Plus 10.0 - Privilege Escalation | 2019-04-05 |
References
→ the Explorer · watch your stack · NVD