CVE-2019-15083

MEDIUM

ManageEngine ServiceDesk Plus < 10500 - Stored Cross-Site Scripting via Workstation Software Name

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-15083. PoCs published by Felipe Molina.

AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in ManageEngine Service Desk Plus 10.0, where a local administrator can inject malicious JavaScript code via the DisplayName registry key of installed software. The PoC creates a new administrator user in ManageEngine Service Desk by leveraging the XSS to execute a CSRF attack.

Description

Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home > Server > <workstation> > software" the administrator of ManageEngine can control what software is installed on the workstation. This table shows all the installed program names in the Software column. In this field, a remote attacker can inject malicious code in order to execute it when the ManageEngine administrator visualizes this page.

Exploits (1)

exploitdb WORKING POC
by Felipe Molina · textwebappsjava
https://www.exploit-db.com/exploits/48473

This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in ManageEngine Service Desk Plus 10.0, where a local administrator can inject malicious JavaScript code via the DisplayName registry key of installed software. The PoC creates a new administrator user in ManageEngine Service Desk by leveraging the XSS to execute a CSRF attack.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine Service Desk Plus 10.0 (10000.0.0.0)
Auth required
Prerequisites: Local administrator access to a workstation managed by ManageEngine Service Desk · Ability to modify registry keys · Access to the ManageEngine Service Desk web interface as an administrator
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.manageengine.com/products/service-desk/readme.html
Third Party Advisory x_refsource_misc
https://www.exploit-db.com/exploits/48473

Scores

CVSS v3 6.1
EPSS 0.0630
EPSS Percentile 92.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
zohocorp/manageengine_servicedesk_plus 10.0.0 (23 CPE variants)
Published May 14, 2020
Tracked Since Feb 18, 2026