Known Vulnerabilities for Manageengine Supportcenter Plus by Zohocorp
Listed below are 9 of the newest known vulnerabilities associated with "Manageengine Supportcenter Plus" by "Zohocorp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-43296 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. | 7.5 - HIGH | 2021-11-30 | 2022-04-27 |
| CVE-2021-43295 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module. | 6.1 - MEDIUM | 2021-11-30 | 2022-04-27 |
| CVE-2021-43294 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module. | 6.1 - MEDIUM | 2021-11-30 | 2022-04-27 |
| CVE-2019-12133 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\... | 7.8 - HIGH | 2019-06-18 | 2020-08-24 |
| CVE-2018-16965 | In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContrac... | 6.1 - MEDIUM | 2018-09-21 | 2018-11-09 |
| CVE-2015-5150 | Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authenticated u... | 3.5 - LOW | 2015-06-30 | 2015-07-01 |
| CVE-2015-5149 | Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to ... | 5.5 - MEDIUM | 2015-06-30 | 2016-12-07 |
| CVE-2015-0866 | Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.9 before hotfix 7941 allow remo... | 4.3 - MEDIUM | 2015-02-02 | 2018-10-09 |
| CVE-2014-100002 | Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrar... | 5 - MEDIUM | 2015-01-13 | 2017-09-08 |