CVE-2019-19799
MEDIUMManageEngine Applications Manager < 14600 - Unauthenticated Information Disclosure via WieldFeedServlet
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-19799. PoCs published by eLeN3Re.
AI-analyzed exploit summary The repository lacks actual exploit code and instead references an external PDF for technical details, which is a common tactic in suspicious repos. The README provides minimal technical information and no functional PoC.
Description
Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
Exploits (1)
gitlab
SUSPICIOUS
by eLeN3Re · poc
https://gitlab.com/eLeN3Re/cve-2019-19799
The repository lacks actual exploit code and instead references an external PDF for technical details, which is a common tactic in suspicious repos. The README provides minimal technical information and no functional PoC.
Classification
Suspicious 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target:
Zoho ManageEngine Applications Manager 14590 and before
No auth needed
Prerequisites:
network access to the target
devstral-2 · analyzed Feb 23, 2026
Full analysis →
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://gitlab.com/eLeN3Re/cve-2019-19799
Vendor Advisory x_refsource_confirm
https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2019-19799.html
Scores
CVSS v3
5.3
EPSS
0.0629
EPSS Percentile
92.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-306
Status
published
Products (2)
zohocorp/manageengine_applications_manager
14.5 (10 CPE variants)
zohocorp/manageengine_applications_manager
< 14.5
Published
Mar 13, 2020
Tracked Since
Feb 18, 2026