Directory Traversal Vulnerability in Zoho ManageEngine Desktop Central
CVE-2022-48362
8.8HIGH
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 25 February 2023
What is CVE-2022-48362?
Zoho ManageEngine Desktop Central and its MSP version prior to 10.1.2137.2 are vulnerable to directory traversal attacks through the computerName parameter sent to the AgentLogUploadServlet. This flaw allows an authenticated attacker to upload malicious code to the server, which can be executed upon restart of the software. The issue could be further exploited if the attacker first gains access by compromising the system using a related authentication bypass vulnerability.