VendorsZoho Corpmanageengine_servicedesk_plusall versions
Vulnerabilities

Zoho Corp ManageEngine ServiceDesk Plus

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2018-7248
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
Published 2018-05-11 · Modified
5.3EPSS 0.061
CVE-2019-15045
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
Published 2019-08-21 · Modified
5.3EPSS 0.049
CVE-2022-25245
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
Published 2022-04-05 · Modified
5.3EPSS 0.013
CVE-2022-40771
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
Published 2022-11-23 · Modified
4.9EPSS 0.037
CVE-2023-29443
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
Published 2023-04-26 · Modified
4.9EPSS 0.030
CVE-2021-46065
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
Published 2022-01-27 · Modified
4.8EPSS 0.917
CVE-2020-6843
Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.
Published 2020-01-23 · Modified
4.8EPSS 0.024
CVE-2019-10273
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
Published 2019-04-04 · Modified
4.31 PoCEPSS 0.076
CVE-2024-27314
Stored XSS Vulnerability
Published 2024-05-27 · Analyzed
2.4EPSS 0.019
← Prev2 / 2