EIP-2026-102407
PRE-CVEManageEngine ServiceDesk Plus 9.2 Build 9207 - Unauthorized Information Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102407. PoCs published by p0z.
AI-analyzed exploit summary The document describes multiple privilege escalation vulnerabilities in ManageEngine ServiceDesk Plus, allowing low-privileged users to access sensitive data such as tickets, attachments, and user assets via parameter manipulation in HTTP requests. It includes proof-of-concept URLs demonstrating the exploits.
Description
ManageEngine ServiceDesk Plus 9.2 Build 9207 - Unauthorized Information Disclosure
Exploits (1)
The document describes multiple privilege escalation vulnerabilities in ManageEngine ServiceDesk Plus, allowing low-privileged users to access sensitive data such as tickets, attachments, and user assets via parameter manipulation in HTTP requests. It includes proof-of-concept URLs demonstrating the exploits.