PT-2018-16908 · Zoho · Manageengine Desktop Central

Publicado

2018-04-18

·

Atualizado

2019-10-03

·

CVE-2018-5340

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Desktop Central versions 10.0.124 through 10.0.184
Description An issue was discovered that allows database access using a superuser account, specifically an account with permission to write to the filesystem via SQL queries.
Recommendations For versions 10.0.124 through 10.0.184, consider restricting superuser account permissions to prevent unauthorized database access and filesystem modifications until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-5340

Produtos afetados

Manageengine Desktop Central