Directory Traversal Vulnerability in Zoho ManageEngine Desktop Central
CVE-2022-48362
8.8HIGH
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 25 February 2023
What is CVE-2022-48362?
Zoho ManageEngine Desktop Central and its MSP version prior to 10.1.2137.2 are vulnerable to directory traversal attacks through the computerName parameter sent to the AgentLogUploadServlet. This flaw allows an authenticated attacker to upload malicious code to the server, which can be executed upon restart of the software. The issue could be further exploited if the attacker first gains access by compromising the system using a related authentication bypass vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved