Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Zoho Manageengine Servicedesk Plus | — | Upgrade Zoho ManageEngine ServiceDesk Plus to the latest version | Dec 18, 2024 | Oct 14, 2022 |
| Zoho Manageengine Servicedesk Plus Msp | — | Upgrade Zoho ManageEngine ServiceDesk Plus MSP to the latest version | Jan 14, 2025 | Sep 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub