Zoho ManageEngine ServiceDesk Plus before 11302 is...
Critical severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 18, 2026
Description
Published by the National Vulnerability Database
Sep 1, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Mar 18, 2026
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
References