Directory Traversal Vulnerability in Zoho ManageEngine Desktop Central
CVE-2020-10859
6.5MEDIUM
What is CVE-2020-10859?
Zoho ManageEngine Desktop Central prior to version 10.0.484 has a security flaw allowing authenticated users to exploit ZIP archive extraction. By crafting a specific AppDependency API request, an attacker can gain the ability to write arbitrary files on the server, potentially compromising the integrity of the system and exposing sensitive information.