Vulnerabilities > CVE-2020-13154 - Missing Authorization vulnerability in Zohocorp Manageengine Servicedesk Plus 11.1

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
zohocorp
CWE-862

Summary

Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.

Vulnerable Configurations

Part Description Count
Application
Zohocorp
13

Common Weakness Enumeration (CWE)