CVE-2020-13154
18.05.2020, 22:15
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_servicedesk_plus | 11.1 |
zohocorp | manageengine_servicedesk_plus | 11.1:11100 |
zohocorp | manageengine_servicedesk_plus | 11.1:11101 |
zohocorp | manageengine_servicedesk_plus | 11.1:11102 |
zohocorp | manageengine_servicedesk_plus | 11.1:11103 |
zohocorp | manageengine_servicedesk_plus | 11.1:11104 |
zohocorp | manageengine_servicedesk_plus | 11.1:11105 |
zohocorp | manageengine_servicedesk_plus | 11.1:11106 |
zohocorp | manageengine_servicedesk_plus | 11.1:11107 |
zohocorp | manageengine_servicedesk_plus | 11.1:11108 |
zohocorp | manageengine_servicedesk_plus | 11.1:11109 |
zohocorp | manageengine_servicedesk_plus | 11.1:11110 |
zohocorp | manageengine_servicedesk_plus | 11.1:11111 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration