Lucene search

K
zdiPiotr Bazydlo (@chudypb) of Trend Micro Zero Day InitiativeZDI-23-229
HistoryMar 09, 2023 - 12:00 a.m.

ManageEngine ServiceDesk Plus MSP generateSQLReport Improper Input Validation Privilege Escalation Vulnerability

2023-03-0900:00:00
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative
www.zerodayinitiative.com
18
manageengine
servicedesk plus msp
privilege escalation
improper input validation
vulnerability
authentication
generatesqlreport

EPSS

0.002

Percentile

59.2%

This vulnerability allows remote attackers to escalate privileges on affected installations of ManageEngine ServiceDesk Plus MSP. Authentication is required to exploit this vulnerability. The specific flaw exists within the generateSQLReport function. The issue results from the lack of proper validation of user-supplied data. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user.

EPSS

0.002

Percentile

59.2%

Related for ZDI-23-229