← Vulnerability feed

Vulnerability record · CVE-2023-23074 · published 1 February 2023

CVE-2023-23074: Zoho ManageEngine ServiceDesk Plus stored XSS via embedded videos

Zohocorp · Manageengine Servicedesk Plus

Zoho ManageEngine ServiceDesk Plus 14 is affected by a cross-site scripting flaw reached through embedding videos in the language component. The CVSS vector shows scope change with low confidentiality and integrity impact, meaning script execution can affect resources beyond the vulnerable component. It matters because ServiceDesk Plus is a widely deployed IT service management platform, and script execution in that context can be used against authenticated staff.

6.1 CVSS 3.1 Medium EPSS 84% · top 0.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe CVSS score is only medium, but the very high EPSS percentile and the sensitive nature of an ITSM platform raise the practical risk.

What it is

Zoho ManageEngine ServiceDesk Plus 14 is affected by a cross-site scripting flaw reached through embedding videos in the language component. The CVSS vector shows scope change with low confidentiality and integrity impact, meaning script execution can affect resources beyond the vulnerable component. It matters because ServiceDesk Plus is a widely deployed IT service management platform, and script execution in that context can be used against authenticated staff.

Impact

An attacker can execute script in the browser context of a victim user, enabling session or credential theft and actions performed as that user. The scope change indicates the injected content can affect components beyond the vulnerable page itself.

Attack surface

Reached over the network with no privileges required, but user interaction is required per the CVSS vector, consistent with a victim viewing crafted content containing the embedded video. No authentication requirement is stated in the vector.

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is very high at 0.83581 (99.669th percentile), indicating elevated predicted exploitation likelihood, though the references carry only vendor advisory tags and no public exploit tag.

What to do

  • Apply the vendor fix referenced in the ManageEngine advisory for CVE-2023-23074 and upgrade ServiceDesk Plus 14 to a patched build.
  • Restrict or disable embedding of external video content in the language component until patched.
  • Deploy output encoding and content sanitization for user-supplied content rendered in ServiceDesk Plus.
  • Enforce a strict Content Security Policy to limit script execution from injected content.
  • Remind users not to open untrusted links or embedded media in ServiceDesk Plus.

Detection

  • Search web and proxy logs for requests to ServiceDesk Plus pages containing embedded video or language component parameters with script-like payloads.
  • Monitor for anomalous script tags, event handlers or javascript: URIs in requests to ServiceDesk Plus endpoints.
  • Alert on suspicious authenticated sessions or actions following viewing of embedded media content.
  • Review ServiceDesk Plus application logs for unexpected changes to language or localization settings.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-23074 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-44077Zoho ManageEngine ServiceDesk Plus unauthenticated RCEZoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling…KEVEPSS 93%analysed9.8CVE-2021-37415Zoho ManageEngine ServiceDesk Plus authentication bypass via REST APIZoho ManageEngine ServiceDesk Plus before build 11302 contains an authentication bypass (CWE-306) that lets a small number of REST-API URLs be reache…KEVEPSS 100%analysed6.5CVE-2019-8394Zoho ManageEngine ServiceDesk Plus unrestricted file upload via login page customizationZoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization fe…KEVEPSS 63%analysed9.8CVE-2021-44526Zohocorp manageengine servicedesk plus vulnerabilityZoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.EPSS 3.2%9.8CVE-2019-8395Zohocorp manageengine servicedesk plus path traversal vulnerabilityAn Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment…EPSS 7.1%8.8CVE-2020-35682Zohocorp manageengine servicedesk plus incorrect authorization vulnerabilityZoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).EPSS 7.2%8.8CVE-2017-9362Zohocorp manageengine servicedesk plus xml external entity (xxe) vulnerabilityManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2023-23074), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.