Record summary

CVE-2019-12252 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.

Description

In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBZoho ManageEngine ServiceDesk Plus < 10.5 - Improper Access RestrictionsExploitDB exploitby VingroupNot analyzed1 file
ExploitDB

PoC details

References

5