

RedLine Stealer – Active IOCs
March 21, 2025
CVE-2025-26336 – Dell PowerEdge Chassis Management Controller Vulnerability
March 21, 2025
RedLine Stealer – Active IOCs
March 21, 2025
CVE-2025-26336 – Dell PowerEdge Chassis Management Controller Vulnerability
March 21, 2025Severity
Medium
Analysis Summary
CVE-2024-50053
A stored cross-site scripting (XSS) vulnerability allowed authenticated technicians to upload a malicious HTML file during task creation. The payload would be executed when other technicians or administrators (or SDAdmins) interact with the file.
Impact
- Cross-Site Scripting
Indicators of Compromise
CVE
- CVE-2024-50053
Affected Vendors
Affected Products
- Zoho ManageEngine ServiceDesk Plus 14910
- Zoho ManageEngine ServiceDesk Plus MSP 14900
- Zoho ManageEngine SupportCentre Plus 14900
Remediation
Refer to Zoho ManageEngine Website for patch, upgrade, or suggested workaround information.