Zoho manageengine servicedesk plus < 10.5 improper access restrictions Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2019-05-22 | Type : webapps | Platform : multiple
This exploit / vulnerability Zoho manageengine servicedesk plus < 10.5 improper access restrictions is for educational purposes only and if it is used you will do on your own risk!


[+] Code ...

# Exploit Title: Zoho ManageEngine ServiceDesk Plus < 10.5 Incorrect Access Control
# Date: 2019-05-21
# Exploit Author: Enter of VinCSS (Vingroup)
# Vendor Homepage: https://www.manageengine.com/products/service-desk
# Version: Zoho ManageEngine ServiceDesk Plus < 10.5
# CVE : CVE-2019-12252



In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the

SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring