Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37653 | Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25. |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 30 Aug 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zohocorp manageengine Endpoint Central
|
|
| CPEs | cpe:2.3:a:zohocorp:manageengine_endpoint_central:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zohocorp manageengine Endpoint Central
|
|
| Metrics |
ssvc
|
ssvc
|
Fri, 30 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 30 Aug 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Stored Cross-site Scripting vulnerability affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800. | Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25. |
| Title | Stored XSS | Incorrect Authorization |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 27 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zohocorp
Zohocorp manageengine Servicedesk Plus Zohocorp manageengine Servicedesk Plus Msp Zohocorp manageengine Supportcenter Plus |
|
| CPEs | cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:14.8:14810:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:14.8:14800:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:14.8:14800:*:*:*:*:*:* |
|
| Vendors & Products |
Zohocorp
Zohocorp manageengine Servicedesk Plus Zohocorp manageengine Servicedesk Plus Msp Zohocorp manageengine Supportcenter Plus |
Fri, 23 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Stored Cross-site Scripting vulnerability affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800. | |
| Title | Stored XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ManageEngine
Published:
Updated: 2024-08-30T18:47:26.580Z
Reserved: 2024-06-20T13:15:39.620Z
Link: CVE-2024-38869
Updated: 2024-08-23T14:38:48.359Z
Status : Modified
Published: 2024-08-23T15:15:15.843
Modified: 2024-08-30T18:15:07.150
Link: CVE-2024-38869
No data.
OpenCVE Enrichment
No data.
EUVD