First published: Thu Jan 18 2024(Updated: )
Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | <14.5 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =14.5-14500 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =14.5-14501 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =14.5-14502 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =14.5-14503 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.