Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
Metrics
Affected Vendors & Products
References
History
Thu, 22 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 22 May 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. | |
Title | Local File Inclusion | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Zohocorp
Published: 2025-05-22T10:31:48.562Z
Updated: 2025-05-22T18:28:27.922Z
Reserved: 2025-04-08T08:14:09.202Z
Link: CVE-2025-3444

Updated: 2025-05-22T18:28:20.808Z

Status : Awaiting Analysis
Published: 2025-05-22T11:15:52.257
Modified: 2025-05-23T15:55:02.040
Link: CVE-2025-3444

No data.