Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16111 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. |
Tue, 17 Jun 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zohocorp
Zohocorp manageengine Servicedesk Plus Msp Zohocorp manageengine Supportcenter Plus |
|
| CPEs | cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:14.9:14900:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:14.9:14910:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:14.9:14900:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:14.9:14910:*:*:*:*:*:* |
|
| Vendors & Products |
Zohocorp
Zohocorp manageengine Servicedesk Plus Msp Zohocorp manageengine Supportcenter Plus |
Thu, 22 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 May 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. | |
| Title | Local File Inclusion | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2025-05-22T18:28:27.922Z
Reserved: 2025-04-08T08:14:09.202Z
Link: CVE-2025-3444
Updated: 2025-05-22T18:28:20.808Z
Status : Analyzed
Published: 2025-05-22T11:15:52.257
Modified: 2025-06-17T20:18:53.007
Link: CVE-2025-3444
No data.
OpenCVE Enrichment
No data.
EUVD