Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
Any version before 14920
affected
Default status
unaffected
Any version before 14920
affected
Description
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
Any version before 14920
Any version before 14920
Credits
Esther
References
www.manageengine.com/.../service-desk-msp/cve-2025-3444.html