First published: Fri Aug 23 2024(Updated: )
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ServiceDesk Plus | <=14.7 | |
Zoho ManageEngine ServiceDesk Plus | =14.8-14810 | |
Zoho ManageEngine ServiceDesk Plus MSP | <=14.7 | |
Zoho ManageEngine ServiceDesk Plus MSP | =14.8-14800 | |
ManageEngine SupportCenter Plus | <=14.7 | |
ManageEngine SupportCenter Plus | =14.8-14800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41150 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
To fix CVE-2024-41150, update to the latest versions of Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, or SupportCenter Plus that are not affected.
CVE-2024-41150 affects ManageEngine ServiceDesk Plus versions up to 14.8-14810, ServiceDesk Plus MSP up to 14.8-14800, and SupportCenter Plus versions up to 14.8-14800.
CVE-2024-41150 impacts Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus.
Yes, CVE-2024-41150 can be exploited remotely due to its nature as a Stored Cross-site Scripting vulnerability.