In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_supportcenter_plus | 11.0-11021 | 11.0-11021.x |
| zohocorp / manageengine_supportcenter_plus | 11.0-11020 | 11.0-11020.x |
| zohocorp / manageengine_supportcenter_plus | 11.0-11022 | 11.0-11022.x |