Manageengine Supportcenter Plus
by Zohocorp
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2014-100002 | 0.08 | — | 0.60 | Jan 13, 2015 | Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket. | |||
| CVE-2023-23076 | 0.04 | — | 0.74 | Feb 1, 2023 | OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. | |||
| CVE-2015-5149 | 0.04 | — | 0.10 | Jun 30, 2015 | Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp. | |||
| CVE-2015-5150 | 0.03 | — | 0.04 | Jun 30, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authenticated users to inject arbitrary web script or HTML via the (1) query parameter in the run_query_editor_query module to CustomReportHandler.do, (2) compAcct… | |||
| CVE-2022-25373 | 0.01 | — | 0.01 | Apr 5, 2022 | Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history. | |||
| CVE-2021-43296 | 0.01 | — | 0.03 | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. | |||
| CVE-2025-3444 | 0.00 | — | 0.01 | May 22, 2025 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. | |||
| CVE-2023-34197 | 0.00 | — | 0.03 | Jul 7, 2023 | Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make… | |||
| CVE-2023-29443 | 0.00 | — | 0.03 | Apr 26, 2023 | Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint. | |||
| CVE-2022-42903 | 0.00 | — | 0.00 | Nov 17, 2022 | Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list. | |||
| CVE-2021-43295 | 0.00 | — | 0.03 | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module. | |||
| CVE-2021-43294 | 0.00 | — | 0.01 | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module. | |||
| CVE-2015-0866 | 0.00 | — | 0.02 | Feb 2, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.9 before hotfix 7941 allow remote attackers to inject arbitrary web script or HTML via the (1) fromCustomer, (2) username, or (3) password parameter to HomePage.do. |
- CVE-2014-100002Jan 13, 2015risk 0.08cvss —epss 0.60
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.
- CVE-2023-23076Feb 1, 2023risk 0.04cvss —epss 0.74
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
- CVE-2015-5149Jun 30, 2015risk 0.04cvss —epss 0.10
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp.
- CVE-2015-5150Jun 30, 2015risk 0.03cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authenticated users to inject arbitrary web script or HTML via the (1) query parameter in the run_query_editor_query module to CustomReportHandler.do, (2) compAcct…
- CVE-2022-25373Apr 5, 2022risk 0.01cvss —epss 0.01
Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.
- CVE-2021-43296Nov 30, 2021risk 0.01cvss —epss 0.03
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.
- CVE-2025-3444May 22, 2025risk 0.00cvss —epss 0.01
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
- CVE-2023-34197Jul 7, 2023risk 0.00cvss —epss 0.03
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make…
- CVE-2023-29443Apr 26, 2023risk 0.00cvss —epss 0.03
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
- CVE-2022-42903Nov 17, 2022risk 0.00cvss —epss 0.00
Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.
- CVE-2021-43295Nov 30, 2021risk 0.00cvss —epss 0.03
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.
- CVE-2021-43294Nov 30, 2021risk 0.00cvss —epss 0.01
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.
- CVE-2015-0866Feb 2, 2015risk 0.00cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.9 before hotfix 7941 allow remote attackers to inject arbitrary web script or HTML via the (1) fromCustomer, (2) username, or (3) password parameter to HomePage.do.