QID 730291
Date Published: 2021-12-08
QID 730291: Zoho ManageEngine SupportCenter Plus Remote Code Execution (RCE) Vulnerability
SupportCenter Plus is a web-based customer support software that lets organizations effectively manage customer tickets, their account and contact information, the service contracts and in the process providing a superior customer experience.
ManageEngine SupportCenter Plus is prone to unauthenticated remote code execution (RCE).
Affected Version:
Zoho ManageEngine SupportCenter Plus 11012 and 11013.
QID Detection logic:(authenticated and unauthenticated)
It checks for vulnerable version of Zoho ManageEngine SupportCenter Plus
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.
Solution
The vendor has released a patch.
Customers are advised to visit release-notes for updates pertaining this vulnerability.
Customers are advised to visit release-notes for updates pertaining this vulnerability.
CVEs related to QID 730291
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SupportCenter Plus |
|