CVE-2019-12252
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring.
MEDIUM · CVSS 6.5
EPSS 0.07041
Schedule remediation
- EPSS percentile: top 8% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0