CVE-2024-41150: Stored XSS
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41150?
CVE-2024-41150 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2024-41150?
To fix CVE-2024-41150, update to the latest versions of Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, or SupportCenter Plus that are not affected.
Which versions are affected by CVE-2024-41150?
CVE-2024-41150 affects ManageEngine ServiceDesk Plus versions up to 14.8-14810, ServiceDesk Plus MSP up to 14.8-14800, and SupportCenter Plus versions up to 14.8-14800.
What products are impacted by CVE-2024-41150?
CVE-2024-41150 impacts Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus.
Can CVE-2024-41150 be exploited remotely?
Yes, CVE-2024-41150 can be exploited remotely due to its nature as a Stored Cross-site Scripting vulnerability.