« Volver al listado

CVE-2024-50053

Estado: AnalizadaMedia (5.4)—

Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-50053",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-50053",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-21T13:58:06.843899Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "affectedData": [
        {
          "vendor": "ManageEngine",
          "product": "ServiceDesk Plus",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "14910",
              "lessThanOrEqual": "14910"
            }
          ],
          "collectionURL": "https://www.manageengine.com/products/service-desk/",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ManageEngine",
          "product": "ServiceDesk Plus MSP",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "14900",
              "lessThanOrEqual": "14900"
            }
          ],
          "collectionURL": "https://www.manageengine.com/products/service-desk-msp/",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ManageEngine",
          "product": "SupportCentre Plus",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "14900",
              "lessThanOrEqual": "14900"
            }
          ],
          "collectionURL": "https://www.manageengine.com/products/support-center/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-03-21T06:15:25.003",
  "references": [
    {
      "url": "https://www.manageengine.com/products/service-desk/CVE-2024-50053.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature."
    },
    {
      "lang": "es",
      "value": "Las versiones de Zohocorp ManageEngine ServiceDesk Plus anteriores a 14920, ServiceDesk Plus MSP y SupportCentre Plus anteriores a 14910 son vulnerables a XSS almacenado en la función de tareas."
    }
  ],
  "lastModified": "2026-06-17T08:03:28.283",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECE2FE6F-AC4D-49DB-A36A-8C76B77F0079",
              "versionEndExcluding": "14.9"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:14.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "859CA019-8026-4178-9A31-0651A853D4E8"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:14.9:14910:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC9B5C66-E0DF-44FE-A900-A3721AF4F95D"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45A0B773-D293-47CA-84A4-E4918F138C3F",
              "versionEndExcluding": "14.9"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:14.9:14900:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B2B72D2-5FD7-4C7F-BE3F-CDA5064E025A"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_supportcentre_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7360E194-C0E4-4870-BCC1-F8E0C05E8649",
              "versionEndExcluding": "14.9"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_supportcentre_plus:14.9:14900:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "233B7D2B-B6A8-492B-9CB6-837C03F8355E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "0fc0942c-577d-436f-ae8e-945763c79b02"
}