Server-Side Request Forgery Vulnerability in Zoho ManageEngine ServiceDesk Plus MSP
CVE-2021-31531
9.8CRITICAL
What is CVE-2021-31531?
Zoho ManageEngine ServiceDesk Plus MSP versions prior to 10521 are susceptible to a Server-Side Request Forgery vulnerability. This security flaw allows an attacker to send crafted requests from the vulnerable server, potentially leading to unauthorized access to internal resources. It is critical for users of this software to apply the latest updates to mitigate associated risks.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved