PT-2025-22455 · Zohocorp · Supportcenter Plus+1

Esther

·

Published

2025-04-10

·

Updated

2025-05-22

·

CVE-2025-3444

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920
Description The issue concerns an authenticated Local File Inclusion (LFI) in the Admin module of the software, specifically where help card content is loaded.
Recommendations For versions below 14920, update to version 14920 or later to resolve the issue. As a temporary workaround, consider restricting access to the Admin module until a patch is available. Avoid using the vulnerable functionality in the Admin module where help card content is loaded until the issue is resolved.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09772
CVE-2025-3444

Affected Products

Manageengine Servicedesk Plus
Supportcenter Plus