Directory Traversal Vulnerability in Zoho ManageEngine Desktop Central
CVE-2022-48362

8.8HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
25 February 2023

What is CVE-2022-48362?

Zoho ManageEngine Desktop Central and its MSP version prior to 10.1.2137.2 are vulnerable to directory traversal attacks through the computerName parameter sent to the AgentLogUploadServlet. This flaw allows an authenticated attacker to upload malicious code to the server, which can be executed upon restart of the software. The issue could be further exploited if the attacker first gains access by compromising the system using a related authentication bypass vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.