Skip to main content

Vendor/product archive

zohocorp / servicedesk_plus CVEs

Beta · best-effort

5 CVEs tagged to zohocorp / servicedesk_plus0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2019-10008

Published Apr 24, 2019

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrat…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4890

Published Apr 14, 2017

ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by lever…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4889

Published Apr 14, 2017

ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4888

Published Apr 14, 2017

Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1479

Published Feb 4, 2015

SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitra…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1