First published: Fri Mar 06 2020(Updated: )
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | <10.0.479 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-10189.
The title of this vulnerability is Zoho ManageEngine Desktop Central File Upload Vulnerability.
This vulnerability allows remote code execution due to deserialization of untrusted data in the FileStorage class, specifically in the getChartImage function in Zoho ManageEngine Desktop Central before version 10.0.474. It is related to the CewolfServlet and MDMLogUploaderServlet servlets.
The Zoho ManageEngine Desktop Central software versions up to and excluding 10.0.479 are affected by this vulnerability.
The severity of CVE-2020-10189 is critical with a score of 9.8.