Description
Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view.
Related CPE's
a
zohocorp
manageengine_servicedesk_plus_msp
11
a
zohocorp
manageengine_supportcenter_plus
26
References
https://www.zerodayinitiative.com/advisories/ZDI-22-1490/
Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-22-1490/
Third Party AdvisoryVDB Entry
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-12T03:15:09.010Z
3 years agoLast modified
2025-05-01T12:15:28.210Z
10 months ago