CVE-2024-27314
Estado: AnalizadaBaja (2.4)—
Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
- Puntuación base: 2.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.91%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-79
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-27314",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-27314",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-05-28T14:17:51.843663Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "0fc0942c-577d-436f-ae8e-945763c79b02",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2.4,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "0fc0942c-577d-436f-ae8e-945763c79b02",
"affectedData": [
{
"vendor": "ManageEngine",
"product": "ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "14730",
"versionType": "14730"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:manageengine:servicedesk_plus:-:*:*:*:*:*:*:*"
],
"vendor": "manageengine",
"product": "servicedesk_plus",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "14730 ",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:manageengine:supportcenter_plus:*:*:*:*:*:*:*:*"
],
"vendor": "manageengine",
"product": "supportcenter_plus",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "14730",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:manageengine:servicedeskplusmsp:servicedeskplusmsp:*:*:*:*:*:*:*"
],
"vendor": "manageengine",
"product": "servicedeskplusmsp",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "14730",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-05-27T07:15:09.297",
"references": [
{
"url": "https://www.manageengine.com/products/service-desk/cve-2024-27314.html",
"tags": [
"Vendor Advisory"
],
"source": "0fc0942c-577d-436f-ae8e-945763c79b02"
},
{
"url": "https://www.manageengine.com/products/service-desk/cve-2024-27314.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "0fc0942c-577d-436f-ae8e-945763c79b02",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users."
},
{
"lang": "es",
"value": "Las versiones de Zoho ManageEngine ServiceDesk Plus inferiores a 14730, ServiceDesk Plus MSP inferiores a 14720 y SupportCenter Plus inferiores a 14730 son vulnerables a XSS almacenado en el menú Acciones personalizadas en los detalles de la solicitud. Esta vulnerabilidad solo puede ser aprovechada por los usuarios de la función SDAdmin."
}
],
"lastModified": "2026-06-17T07:19:37.957",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "290E0FBA-79EA-4510-A53A-34220253A9C1",
"versionEndIncluding": "14.6"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:14.7:14700:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1EDFAB9B-9DC8-432C-B191-EA0F31800E03"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:14.7:14710:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE0513D6-ED58-4498-ADD1-3F4C86B64FA3"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:14.7:14720:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC72689A-18BD-42B0-90AD-39112EBA80F1"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEBBD6E9-B17F-413F-9AC3-2D7F86274743",
"versionEndIncluding": "14.6"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:14.7:14700:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91D417CC-9745-402E-A7E6-AE2D5C23E132"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:14.7:14710:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A56DBA9-0983-4329-B77A-CF84112B0C06"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE784E2C-B217-4FE8-A6E4-D378356AE1AB",
"versionEndIncluding": "14.6"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:14.7:14700:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7CDCEC2-9D93-41FB-9FC0-556EE84C033E"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:14.7:14710:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C420DA1-CC5C-4A9B-B428-F3816B10F822"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "0fc0942c-577d-436f-ae8e-945763c79b02"
}