CVE-2015-1479: Zohocorp ServiceDesk Plus
Medium severity, CVSS 6.5. EPSS: 3.9% chance of exploitation in the next 30 days.
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitrary SQL commands via the site parameter.
Affected products
- Zohocorp ServiceDesk Plus: up to and including 9.0
Published 2015-02-04. Last modified 2026-06-17.