PT-2018-11528 · Zoho · Zoho Manageengine Desktop Central
Xiaotian.Wang
·
Publicado
2018-06-29
·
Atualizado
2018-08-20
·
CVE-2018-12999
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Desktop Central version 10.0.255
Description
The issue allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server. This is achieved by including a
computerName=../ substring in the request to the "/agenttrayicon" API endpoint.Recommendations
For Zoho ManageEngine Desktop Central version 10.0.255, consider restricting access to the AgentTrayIconServlet to prevent unauthorized file deletion until a patch is available. As a temporary workaround, avoid using the
computerName variable in the affected API endpoint.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zoho Manageengine Desktop Central