CVE-2023-49943
18.01.2024, 19:15
Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_servicedesk_plus_msp | 𝑥 < 14.5 |
| zohocorp | manageengine_servicedesk_plus_msp | 14.5:14500 |
| zohocorp | manageengine_servicedesk_plus_msp | 14.5:14501 |
| zohocorp | manageengine_servicedesk_plus_msp | 14.5:14502 |
| zohocorp | manageengine_servicedesk_plus_msp | 14.5:14503 |
𝑥
= Vulnerable software versions