CVE-2019-10273
MEDIUMManageEngine ServiceDesk Plus 9.3 - Authenticated User Enumeration via Login Page
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-10273. PoCs published by Operat0r.
AI-analyzed exploit summary This is a detailed writeup describing a user enumeration vulnerability (CVE-2019-10273) in ManageEngine ServiceDesk Plus 9.3. It explains the steps to exploit the flaw, which involves leveraging an authentication bypass to enumerate active users.
Description
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
Exploits (1)
This is a detailed writeup describing a user enumeration vulnerability (CVE-2019-10273) in ManageEngine ServiceDesk Plus 9.3. It explains the steps to exploit the flaw, which involves leveraging an authentication bypass to enumerate active users.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N