QID 378343

Date Published: 2023-05-08

QID 378343: Zoho ManageEngine ServiceDesk Plus and ServiceDesk Plus MSP Stored Cross-Site Scripting (XSS) Vulnerability

Zoho ManageEngine ServiceDesk Plus and ServiceDesk Plus MSP are vulnerable to stored cross-site scripting (XSS) vulnerability.

A stored cross-site scripting (XSS) vulnerability allowed any low-privileged user to inject malicious JavaScript when associating a service request from the purchase order details page. The JavaScript is executed when the target user views the Associate Service Requests list view in the Purchase Order details page.

Affected Versions:
ServiceDesk Plus 14102 and below
ServiceDesk Plus MSP 13001 and below

QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus and ServiceDesk Plus MSP by reading the version from buildinfo.xml file.

Successful exploitation of this vulnerability may allow an low-privileged attacker to inject malicious JavaScript when associating a service request from the purchase order details page.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory

    Vendor References

    CVEs related to QID 378343

    Software Advisories
    Advisory ID Software Component Link
    Zoho ManageEngine Security Advisory URL Logo www.manageengine.com/products/service-desk/CVE-2023-23073.html