CVE-2018-5341: Input Validation
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5341?
CVE-2018-5341 is a vulnerability in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184 that allows for a missing server-side check on the file type/extension when uploading and modifying scripts.
How severe is CVE-2018-5341?
CVE-2018-5341 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2018-5341?
Zoho ManageEngine Desktop Central versions 10.0.124 and 10.0.184 are affected by CVE-2018-5341.
How can I fix CVE-2018-5341?
To fix CVE-2018-5341, update Zoho ManageEngine Desktop Central to a version that includes the necessary security patches.
Where can I find more information about CVE-2018-5341?
You can find more information about CVE-2018-5341 on the Zoho ManageEngine Desktop Central website or the NCC Group technical advisory.