CVE Details
Basic Information
| Title |
CVE-2025-3444 Local File Inclusion |
| Type |
cve |
| Published |
2025-05-22T10:31:48 |
| Last Seen |
2025-05-22T10:52:05 |
CVSS Information
| Base Score |
6.5 (MEDIUM) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
LOW |
| User Interaction |
NONE |
| Scope |
UNCHANGED |
| Confidentiality Impact |
HIGH |
| Integrity Impact |
NONE |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
An authenticated Local File Inclusion (LFI) vulnerability exists in Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920. This vulnerability allows an authenticated attacker to access sensitive files on the server, potentially leading to information disclosure. The vulnerability is in the Admin module, specifically in the help card content handling. |
| AI Severity |
Medium |
| Vendor |
Zohocorp |
| Product |
ManageEngine ServiceDesk Plus MSP, SupportCenter Plus |
| Affected Version |
below 14920 |
Additional Information
| CVE List |
CVE-2025-3444 |
| CWE List |
CWE-434 |
| Bulletin Family |
cve |
Description
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is…
CVSS Score Summary
Base Score: %!f(string=#) (MEDIUM)
View Full CVE Details