← Vulnerability feed

Vulnerability record · CVE-2019-10273 · published 4 April 2019

CVE-2019-10273: Zohocorp manageengine servicedesk plus improper authentication vulnerability

Zohocorp · Manageengine Servicedesk Plus

Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

4.3 CVSS 3.0 Medium EPSS 7.6% · top 5.6% CWE-287 · Improper authentication
4.3CVSS 3.0 base score, v2 4.0
7.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-10273 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-44077Zoho ManageEngine ServiceDesk Plus unauthenticated RCEZoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling…KEVEPSS 93%analysed9.8CVE-2021-37415Zoho ManageEngine ServiceDesk Plus authentication bypass via REST APIZoho ManageEngine ServiceDesk Plus before build 11302 contains an authentication bypass (CWE-306) that lets a small number of REST-API URLs be reache…KEVEPSS 100%analysed6.5CVE-2019-8394Zoho ManageEngine ServiceDesk Plus unrestricted file upload via login page customizationZoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization fe…KEVEPSS 63%analysed9.8CVE-2021-44526Zohocorp manageengine servicedesk plus vulnerabilityZoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.EPSS 3.2%9.8CVE-2019-8395Zohocorp manageengine servicedesk plus path traversal vulnerabilityAn Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment…EPSS 7.1%8.8CVE-2020-35682Zohocorp manageengine servicedesk plus incorrect authorization vulnerabilityZoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).EPSS 7.2%8.8CVE-2017-9362Zohocorp manageengine servicedesk plus xml external entity (xxe) vulnerabilityManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2019-10273), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.