ZeroHour

CVE-2025-3444

CVSS 3.1
6.5 medium
EPSS
2%p73
Published
()
Modified
Description

Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.

Vendors
zohocorp
Products
manageengine servicedesk plus msp, manageengine supportcenter plus
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.