CVE-2025-11248
LOWZohoCorp ManageEngine Endpoint Central <11.4.2528.05 - Info Disclosure
Title source: llmDescription
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.
Scores
CVSS v3
3.2
EPSS
0.0025
EPSS Percentile
48.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Classification
CWE
CWE-532
Status
published
Affected Products (1)
zohocorp/manageengine_endpoint_central
< 11.4.2528.05
Timeline
Published
Oct 27, 2025
Tracked Since
Feb 18, 2026