Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.manageengine.com/products/service-desk/on-premises/readme.html | vendor advisory |
https://gitlab.com/eLeN3Re/CVE-2020-14048 | third party advisory |