CVE-2020-13154
MEDIUMZoho ManageEngine Service Plus <11.1.11112 - Info Disclosure
Title source: llmDescription
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
Exploits (1)
Scores
CVSS v3
6.5
EPSS
0.0051
EPSS Percentile
66.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-862
Status
published
Products (1)
zohocorp/manageengine_servicedesk_plus
11.1 (13 CPE variants)
Published
May 18, 2020
Tracked Since
Feb 18, 2026