CVE-2020-13154
MEDIUMZoho ManageEngine Service Plus <11.1.11112 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-13154. PoCs published by eLeN3Re.
AI-analyzed exploit summary The repository lacks actual exploit code and instead references an external PDF for technical details, which is a common tactic in suspicious repos. The README provides minimal technical information and no functional PoC.
Description
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
Exploits (1)
The repository lacks actual exploit code and instead references an external PDF for technical details, which is a common tactic in suspicious repos. The README provides minimal technical information and no functional PoC.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N