CVE-2024-50053 Details
Description
Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.
A stored cross-site scripting vulnerability has been identified in ManageEngine ServiceDesk Plus versions prior to 14920, as well as in ServiceDesk Plus MSP and SupportCentre Plus versions prior to 14910. This vulnerability allows authenticated technicians to upload malicious HTML files during task creation. The injected scripts are executed when other technicians, administrators, or SDAdmins interact with the file.
Users can upgrade to version 14920 for ServiceDesk Plus, or to version 14910 for ServiceDesk Plus MSP and SupportCentre Plus. Instructions for downloading the latest service pack are available on the ManageEngine website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/service-desk/CVE-2024-50053.html | ManageEngine | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ManageEngine |
Affected Products
| Product | Versions |
|---|---|
| zohocorp manageengine servicedesk plus | < 14.9 14.9 14.9 14910 |
CPE
Remediation
| |
| zohocorp manageengine servicedesk plus msp | < 14.9 14.9 14900 |
CPE
Remediation
| |
| zohocorp manageengine supportcentre plus | < 14.9 14.9 14900 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 27, 2025 | Initial Analysis | [email protected] |
| Mar 21, 2025 | New CVE Received | ManageEngine |