Zohocorp Manageengine Servicedesk Plus vulnerabilities

50 known vulnerabilities affecting zohocorp/manageengine_servicedesk_plus.

Total CVEs
50
CISA KEV
4
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL5HIGH11MEDIUM33LOW1

Vulnerabilities

Page 3 of 3
CVE-2019-12541MEDIUMCVSS 6.1PoCv9.32019-06-05
CVE-2019-12541 [MEDIUM] CWE-79 CVE-2019-12541: An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSear An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
nvd
CVE-2019-12189MEDIUMCVSS 6.1PoCv9.32019-05-21
CVE-2019-12189 [MEDIUM] CWE-79 CVE-2019-12189: An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do s An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
nvd
CVE-2019-12252MEDIUMCVSS 6.5PoC≤ 10.52019-05-21
CVE-2019-12252 [MEDIUM] CWE-639 CVE-2019-12252: In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can vie In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring.
nvd
CVE-2019-10273MEDIUMCVSS 4.3PoCv9.32019-04-04
CVE-2019-10273 [MEDIUM] CWE-287 CVE-2019-10273: Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 softwar Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
nvd
CVE-2017-9362HIGHCVSS 8.8fixed in 9.32019-03-25
CVE-2017-9362 [HIGH] CWE-611 CVE-2017-9362: ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
nvd
CVE-2017-9376MEDIUMCVSS 6.5fixed in 9.32019-03-25
CVE-2017-9376 [MEDIUM] CWE-20 CVE-2017-9376: ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defMo ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
nvd
CVE-2019-8395CRITICALCVSS 9.8fixed in 10.02019-02-17
CVE-2019-8395 [CRITICAL] CWE-22 CVE-2019-8395: An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plu An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
nvd
CVE-2019-8394MEDIUMCVSS 6.5KEVPoCfixed in 10.0.0v10.0.02019-02-17
CVE-2019-8394 [MEDIUM] CWE-434 CVE-2019-8394: Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload a Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
nvd
CVE-2018-7248MEDIUMCVSS 5.3v9.32018-05-11
CVE-2018-7248 [MEDIUM] CVE-2018-7248: An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
nvd
CVE-2018-5799MEDIUMCVSS 6.1fixed in 94032018-03-30
CVE-2018-5799 [MEDIUM] CWE-79 CVE-2018-5799: In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.
nvd