QID 378354

Date Published: 2023-04-13

QID 378354: Zoho ManageEngine ServiceDesk Plus MSP and SupportCenter Plus Privilege Escalation Vulnerability

Zoho ManageEngine ServiceDesk Plus MSP and SupportCenter Plus are vulnerable to privilege escalation vulnerability when exporting requests from the request list view.

Users with lower access privileges are able to access restricted data by manipulating the URL, while exporting requests from the list view.

Affected Versions:
ManageEngine ServiceDesk Plus MSP versions 10608 and below
ManageEngine SupportCenter Plus versions 11024 and below

QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus MSP and SupportCenter Plus by reading the version from buildinfo.xml file.

Successful exploitation of this vulnerability may allow an attacker to gain unauthorized access to restricted data.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory

    Vendor References

    CVEs related to QID 378354

    Software Advisories
    Advisory ID Software Component Link
    Zoho ManageEngine Security Advisory URL Logo www.manageengine.com/products/service-desk-msp/cve-2022-40773.html