Severity
8.8HIGH
EPSS
0.9%
top 23.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-mfq3-8xp6-5mj3: Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation2022-11-12
CVEList
CVE-2022-40773: Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation2022-11-12
CVE-2022-40773 (HIGH CVSS 8.8) | Zoho ManageEngine ServiceDesk Plus | cvebase.io