Vulnerabilities > CVE-2020-13154 - Missing Authorization vulnerability in Zohocorp Manageengine Servicedesk Plus 11.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 13 |