VendorsZoho Corpmanageengine_servicedesk_plus13.0
Vulnerabilities

Zoho Corp ManageEngine ServiceDesk Plus 13.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-35403
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)
Published 2022-07-12 · Modified
7.5EPSS 0.060
CVE-2022-40770
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
Published 2022-11-23 · Modified
7.2EPSS 0.813
CVE-2023-23077
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
Published 2023-02-01 · Modified
6.1EPSS 0.028
CVE-2022-25245
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
Published 2022-04-05 · Modified
5.3EPSS 0.013