CVE-2019-12252: Zohocorp ManageEngine ServiceDesk Plus

Medium severity, CVSS 6.5. EPSS: 8.2% chance of exploitation in the next 30 days.

In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.

Affected products

  • Zohocorp ManageEngine ServiceDesk Plus: up to and including 10.5

Published 2019-05-21. Last modified 2026-06-17.