Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_servicedesk_plus | Zohocorp | * | 13.0 (excluding) |
Manageengine_servicedesk_plus | Zohocorp | 13.0-13000 (including) | 13.0-13000 (including) |
Manageengine_servicedesk_plus | Zohocorp | 13.0-13001 (including) | 13.0-13001 (including) |
Manageengine_servicedesk_plus | Zohocorp | 13.0-13002 (including) | 13.0-13002 (including) |
Manageengine_servicedesk_plus | Zohocorp | 13.0-13003 (including) | 13.0-13003 (including) |
Manageengine_servicedesk_plus | Zohocorp | 13.0-13004 (including) | 13.0-13004 (including) |
Manageengine_servicedesk_plus | Zohocorp | 13.0-13005 (including) | 13.0-13005 (including) |
Manageengine_servicedesk_plus | Zohocorp | 13.0-13006 (including) | 13.0-13006 (including) |
Manageengine_servicedesk_plus | Zohocorp | 13.0-13007 (including) | 13.0-13007 (including) |