CVE-2018-12999: Input Validation
Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12999?
CVE-2018-12999 is a vulnerability in Zoho ManageEngine Desktop Central 10.0.255 that allows attackers to delete certain files on the web server without login.
What is the severity of CVE-2018-12999?
CVE-2018-12999 has a severity rating of 7.5 out of 10, which is considered high.
How can an attacker exploit CVE-2018-12999?
An attacker can exploit CVE-2018-12999 by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.
Is there a patch available for CVE-2018-12999?
There is currently no information available about a patch for CVE-2018-12999.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-12999?
The Common Weakness Enumeration (CWE) ID for CVE-2018-12999 is 20, which refers to Improper Input Validation.