Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
2023-07-07T13:15:09.273
2024-11-21T08:06:45.420
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zohocorp | manageengine_servicedesk_plus | < 14.2 | Yes |
Application | zohocorp | manageengine_servicedesk_plus | 14.2 | Yes |
Application | zohocorp | manageengine_servicedesk_plus | 14.2 | Yes |
Application | zohocorp | manageengine_servicedesk_plus_msp | < 14.2 | Yes |
Application | zohocorp | manageengine_servicedesk_plus_msp | 14.2 | Yes |
Application | zohocorp | manageengine_servicedesk_plus_msp | 14.2 | Yes |
Application | zohocorp | manageengine_servicedesk_plus_msp | 14.2 | Yes |
Application | zohocorp | manageengine_supportcenter_plus | < 14.2 | Yes |
Application | zohocorp | manageengine_supportcenter_plus | 14.2 | Yes |
Application | zohocorp | manageengine_supportcenter_plus | 14.2 | Yes |