Loading vulnerability details…
CVSS v3.1
9.8
EPSS
93.30%
Published
Nov 29, 2021
Modified
Oct 31, 2025
CISA Known Exploited Vulnerability
Added: 2021-12-01 · Due: 2021-12-15
Apply updates per vendor instructions.
Public PoC / Exploit (4)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (73)
...and 23 more
References (11)