CVE-2019-12538
- EPSS 2.01%
- Veröffentlicht 05.06.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:23:03
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
CVE-2019-12252
- EPSS 7.17%
- Veröffentlicht 21.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:29
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring.
CVE-2019-12189
- EPSS 6.9%
- Veröffentlicht 21.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:23
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
CVE-2019-10273
- EPSS 15.37%
- Veröffentlicht 04.04.2019 16:29:02
- Zuletzt bearbeitet 21.11.2024 04:18:47
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and v...
CVE-2017-9376
- EPSS 0.61%
- Veröffentlicht 25.03.2019 16:29:03
- Zuletzt bearbeitet 21.11.2024 03:35:57
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
CVE-2017-9362
- EPSS 0.28%
- Veröffentlicht 25.03.2019 16:29:03
- Zuletzt bearbeitet 21.11.2024 03:35:55
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
CVE-2019-8395
- EPSS 12.19%
- Veröffentlicht 17.02.2019 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:50
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
CVE-2019-8394
- EPSS 87.94%
- Veröffentlicht 17.02.2019 04:29:00
- Zuletzt bearbeitet 14.03.2025 18:24:37
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
CVE-2018-7248
- EPSS 4.68%
- Veröffentlicht 11.05.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:52
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon d...
CVE-2018-5799
- EPSS 0.63%
- Veröffentlicht 30.03.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:25
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.