VendorsZoho Corpmanageengine_servicedesk_plus9.3
Vulnerabilities

Zoho Corp ManageEngine ServiceDesk Plus 9.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2021-44526
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
Published 2021-12-23 · Modified
9.8EPSS 0.032
CVE-2020-14048
Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.
Published 2020-06-12 · Modified
7.5EPSS 0.048
CVE-2021-20080
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.
Published 2021-04-09 · Modified
6.1EPSS 0.931
CVE-2019-12543
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.
Published 2019-06-05 · Modified
6.11 PoCEPSS 0.061
CVE-2019-12538
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
Published 2019-06-05 · Modified
6.11 PoCEPSS 0.060
CVE-2019-12541
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
Published 2019-06-05 · Modified
6.11 PoCEPSS 0.060
CVE-2019-12542
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
Published 2019-06-05 · Modified
6.11 PoCEPSS 0.060
CVE-2019-12189
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
Published 2019-05-21 · Modified
6.11 PoCEPSS 0.059
CVE-2018-7248
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
Published 2018-05-11 · Modified
5.3EPSS 0.061
CVE-2019-10273
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
Published 2019-04-04 · Modified
4.31 PoCEPSS 0.076