CVE-2020-13154

Published
View on NVD ↗
CVSS v3
6.5
MEDIUM
CVSS v2
4
MEDIUM
Affected
1
PROJECT

Description

Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.

Zoho ManageEngine Service Desk Plus 11.1 build 11111 and before allow low privileged authenticated users to disclose File Protection password.
GitLabGitLab