AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.manageengine.com/products/service-desk/readme.html | vendor advisory |
http://seclists.org/fulldisclosure/2019/Aug/17 | mailing list exploit third party advisory |
http://packetstormsecurity.com/files/154183/Zoho-Corporation-ManageEngine-ServiceDesk-Plus-Information-Disclosure.html | exploit vdb entry third party advisory |