CVE-2023-23078: Zohocorp ManageEngine ServiceDesk Plus
Medium severity, CVSS 6.1. EPSS: 2.8% chance of exploitation in the next 30 days.
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
Affected products
- Zohocorp ManageEngine ServiceDesk Plus: version 14.0 only
Published 2023-02-01. Last modified 2026-06-17.