CVE-2020-10189: Zoho ManageEngine Desktop Central File Upload Vulnerability
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
Other sources
Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-10189.
What is the title of this vulnerability?
The title of this vulnerability is Zoho ManageEngine Desktop Central File Upload Vulnerability.
What is the description of this vulnerability?
This vulnerability allows remote code execution due to deserialization of untrusted data in the FileStorage class, specifically in the getChartImage function in Zoho ManageEngine Desktop Central before version 10.0.474. It is related to the CewolfServlet and MDMLogUploaderServlet servlets.
What software is affected by this vulnerability?
The Zoho ManageEngine Desktop Central software versions up to and excluding 10.0.479 are affected by this vulnerability.
What is the severity of CVE-2020-10189?
The severity of CVE-2020-10189 is critical with a score of 9.8.