Record summary

CVE-2019-10273 has a selected CVSS score of 4.3 (medium); EIP currently links 1 catalogued exploit.

Description

Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBManageEngine ServiceDesk Plus 9.3 - User EnumerationExploitDB exploitby Operat0rNot analyzed1 file
ExploitDB

PoC details

References

4