Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_servicedesk_plus | Zohocorp | 11.1 (including) | 11.1 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11100 (including) | 11.1-11100 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11101 (including) | 11.1-11101 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11102 (including) | 11.1-11102 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11103 (including) | 11.1-11103 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11104 (including) | 11.1-11104 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11105 (including) | 11.1-11105 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11106 (including) | 11.1-11106 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11107 (including) | 11.1-11107 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11108 (including) | 11.1-11108 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11109 (including) | 11.1-11109 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11110 (including) | 11.1-11110 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.1-11111 (including) | 11.1-11111 (including) |