CVE-2020-13154
Published
CVSS v3
6.5
MEDIUM
CVSS v2
4
MEDIUM
Affected
1
PROJECT
Description
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
Zoho ManageEngine Service Desk Plus 11.1 build 11111 and before allow low privileged authenticated users to disclose File Protection password.