CVE-2023-49943: Zohocorp ManageEngine ServiceDesk Plus Msp
Medium severity, CVSS 5.4. EPSS: 1.8% chance of exploitation in the next 30 days.
Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.
Affected products
- Zohocorp ManageEngine ServiceDesk Plus Msp: before 14.5 (fixed in 14.5); version 14.5 only
Published 2024-01-18. Last modified 2026-06-17.