QID 376151
Date Published: 2021-12-10
QID 376151: Zoho ManageEngine ServiceDesk Plus MSP Remote Code Execution (RCE) Vulnerability
ServiceDesk Plus MSP is a web based, full-fledged ITSM suite designed specifically for managed service providers. This all-in-one ITSM solution delivers comprehensive help desk, service desk, account management, asset management, remote controls and advanced reporting in a multi-tenant architecture with robust data segregation.
Zoho ManageEngine ServiceDesk Plus MSP from 10527 to 10529 allows unauthenticated remote code execution (RCE).
Affected Versions:
Zoho ServiceDesk Plus MSP from 10527 to 10529
QID Detection logic:(authenticated and unauthenticated)
It checks for vulnerable version of Zoho ManageEngine ServiceDesk Plus MSP
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the target system.
CVEs related to QID 376151
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ServiceDesk Plus MSP |
|