CVE-2024-41150: Zohocorp ManageEngine ServiceDesk Plus

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.

Affected products

  • Zohocorp ManageEngine ServiceDesk Plus: up to and including 14.7; version 14.8 only
  • Zohocorp ManageEngine ServiceDesk Plus Msp: up to and including 14.7; version 14.8 only
  • Zohocorp ManageEngine SupportCenter Plus: up to and including 14.7; version 14.8 only

Published 2024-08-23. Last modified 2026-06-17.