Stored cross-site scripting in Zoho Corporation products - CVE-2024-50053
Published: April 7, 2025
Vulnerability details
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Zoho ManageEngine SupportCenter Plus
Zoho ManageEngine ServiceDesk Plus MSP
How to mitigate CVE-2024-50053
Zoho ManageEngine SupportCenter Plus - update to 14910
Zoho ManageEngine ServiceDesk Plus MSP - update to 14910