Severity
6.5MEDIUM
EPSS
1.5%
top 18.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22

Description

Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

2
CVEList
Local File Inclusion2025-05-22
GHSA
GHSA-mjxx-858f-xw63: Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in t2025-05-22

📋Vendor Advisories

1
Microsoft
Linux kernel bpf verifier incorrect mod32 truncation2021-03-09
CVE-2025-3444 (MEDIUM CVSS 6.5) | Zohocorp ManageEngine ServiceDesk P | cvebase.io