VendorsZoho Corpmanageengine_servicedesk_plus10.5
Vulnerabilities

Zoho Corp ManageEngine ServiceDesk Plus 10.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-44526
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
Published 2021-12-23 · Modified
9.8EPSS 0.032
CVE-2020-14048
Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.
Published 2020-06-12 · Modified
7.5EPSS 0.048
CVE-2021-31160
Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.
Published 2021-06-29 · Modified
7.5EPSS 0.035
CVE-2021-20080
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.
Published 2021-04-09 · Modified
6.1EPSS 0.931
CVE-2019-12539
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
Published 2019-07-11 · Modified
6.1EPSS 0.025
CVE-2019-12540
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
Published 2019-07-11 · Modified
6.1EPSS 0.023