VYPR

Manageengine Servicedesk Plus Msp

by Zohocorp

CVEs (26)

  • CVE-2023-6105MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt…

  • CVE-2023-49943MedJan 18, 2024
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

  • CVE-2023-34197MedJul 7, 2023
    risk 0.35cvss 5.4epss 0.04

    Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make…

  • CVE-2023-29443MedApr 26, 2023
    risk 0.32cvss 4.9epss 0.03

    Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

  • CVE-2022-40771MedNov 23, 2022
    risk 0.32cvss 4.9epss 0.04

    Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.

  • CVE-2024-27314LowMay 27, 2024
    risk 0.16cvss 2.4epss 0.02

    Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users.

Page 2 of 2