CVE-2019-15083
- EPSS 1.64%
- Veröffentlicht 14.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:01
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code...
CVE-2020-6843
- EPSS 1.88%
- Veröffentlicht 23.01.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:36:16
Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.
CVE-2019-15045
- EPSS 2.51%
- Veröffentlicht 21.08.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:27:56
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
CVE-2019-15046
- EPSS 5.35%
- Veröffentlicht 14.08.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:56
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
CVE-2019-12540
- EPSS 4.72%
- Veröffentlicht 11.07.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:03
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
CVE-2019-12539
- EPSS 5.5%
- Veröffentlicht 11.07.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:03
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
CVE-2019-12133
- EPSS 0.06%
- Veröffentlicht 18.06.2019 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:22:17
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such...
CVE-2019-12543
- EPSS 2.01%
- Veröffentlicht 05.06.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:23:04
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.
CVE-2019-12542
- EPSS 2.01%
- Veröffentlicht 05.06.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:23:04
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
CVE-2019-12541
- EPSS 2.01%
- Veröffentlicht 05.06.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:23:04
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.