CVE-2025-3444: Zohocorp ManageEngine ServiceDesk Plus Msp
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
Affected products
- Zohocorp ManageEngine ServiceDesk Plus Msp: up to and including 14.8; version 14.9 only
- Zohocorp ManageEngine SupportCenter Plus: up to and including 14.8; version 14.9 only
Published 2025-05-22. Last modified 2026-06-17.