Rewterz
RedLine Stealer – Active IOCs
March 21, 2025
Rewterz
CVE-2025-26336 – Dell PowerEdge Chassis Management Controller Vulnerability
March 21, 2025

CVE-2024-50053 – Zoho ManageEngine ServiceDesk Plus Vulnerability

Severity

Medium

Analysis Summary

CVE-2024-50053

A stored cross-site scripting (XSS) vulnerability allowed authenticated technicians to upload a malicious HTML file during task creation. The payload would be executed when other technicians or administrators (or SDAdmins) interact with the file.

Impact

  • Cross-Site Scripting

Indicators of Compromise

CVE

  • CVE-2024-50053

Affected Vendors

Zoho

Affected Products

  • Zoho ManageEngine ServiceDesk Plus 14910
  • Zoho ManageEngine ServiceDesk Plus MSP 14900
  • Zoho ManageEngine SupportCentre Plus 14900

Remediation

Refer to Zoho ManageEngine Website for patch, upgrade, or suggested workaround information.

Zoho ManageEngine Website