CVE-2024-50053

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 21, 2025
Updated: Mar 27, 2025
CWE ID 79

Summary

CVE-2024-50053 is a newly disclosed vulnerability affecting Zohocorp's ManageEngine ServiceDesk Plus versions below 14920 and ServiceDesk Plus MSP and SupportCentre Plus versions below 14910. Maliciously crafted input in the task feature can be stored and executed as Cross-Site Scripting (XSS) attacks, potentially allowing attackers to steal sensitive data or gain unauthorized access to user sessions. This issue poses a serious risk to organizations using these outdated software versions and requires immediate patching to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share