Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
CVE ID: CVE-2025-3444
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.5
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vendor: ManageEngine
Product: ServiceDesk Plus MSP, SupportCenter Plus
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 15.13% (scored less or equal to compared to others)
EPSS Date: 2025-06-19 (when was this score calculated)