eLeN3Re/CVE-2020-13154

eLeN3Re/CVE-2020-13154

Releases0
Zoho ManageEngine Service Desk Plus 11.1 build 11111 and before allow low privileged authenticated users to disclose File Protection password.

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM4 MEDIUM

Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.