CVE-2024-50053 - CVE House
Back to Database
Status published Medium CVE-2024-50053

Stored XSS

Vulnerability Description

Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-50053

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • vuhd and brocked200 from Viettel Cyber Security

Affected Vendor

ManageEngine

View all reports →

Affected Software

ServiceDesk Plus, ServiceDesk Plus MSP, SupportCentre Plus
Vulnerable Versions:
0

Timeline

Official Publish: March 21st, 2025
Last Modified: May 5th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N

Weaknesses (CWE)