ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.035
EPSS Ranking 87.5%