nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-3444 CVE-2025-3444
MEDIUM
Local File Inclusion
Record summary
CVE-2025-3444 has a selected CVSS score of 6.5 (medium).
Description
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ServiceDesk Plus MSPBrowse ManageEngine / ServiceDesk Plus MSPDefault status: unaffected | CVE List | Before 14920 | affected |
SupportCenter PlusBrowse ManageEngine / SupportCenter PlusDefault status: unaffected | CVE List | Before 14920 | affected |
References
2manageengine.com
https://www.manageengine.com/products/service-desk-msp/cve-2025-3444.html