Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://www.manageengine.com/products/service-desk-msp/cve-2022-40773.html | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-22-1490/ | vdb entry third party advisory |