CVE-2025-3444
—CVSS 3.1
6.5 medium
EPSS
2%p73
Published
()
Modified
Description
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
- Vendors
- zohocorp
- Products
- manageengine servicedesk plus msp, manageengine supportcenter plus
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.