zoho manageengine servicedesk plus < 10.5 improper access restrictions
▸▸▸ Exploit & Vulnerability >> webapps exploit & multiple vulnerability
# Exploit Title: Zoho ManageEngine ServiceDesk Plus < 10.5 Incorrect Access Control # Date: 2019-05-21 # Exploit Author: Enter of VinCSS (Vingroup) # Vendor Homepage: https://www.manageengine.com/products/service-desk # Version: Zoho ManageEngine ServiceDesk Plus < 10.5 # CVE : CVE-2019-12252 In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring
Zoho manageengine servicedesk plus < 10.5 improper access restrictions Vulnerability / Exploit Source : Zoho manageengine servicedesk plus < 10.5 improper access restrictions