CVE-2025-3444
22.05.2025, 11:15
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.Enginsight
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_servicedesk_plus_msp | 𝑥 ≤ 14.8 |
| zohocorp | manageengine_servicedesk_plus_msp | 14.9:14900 |
| zohocorp | manageengine_servicedesk_plus_msp | 14.9:14910 |
| zohocorp | manageengine_supportcenter_plus | 𝑥 ≤ 14.8 |
| zohocorp | manageengine_supportcenter_plus | 14.9:14900 |
| zohocorp | manageengine_supportcenter_plus | 14.9:14910 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration