Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_servicedesk_plus | Zohocorp | * | 14.2 (excluding) |
Manageengine_servicedesk_plus | Zohocorp | 14.2-14200 (including) | 14.2-14200 (including) |
Manageengine_servicedesk_plus | Zohocorp | 14.2-14201 (including) | 14.2-14201 (including) |