CVE-2019-12252
21.05.2019, 18:29
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_servicedesk_plus | 𝑥 ≤ 10.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References