PT-2018-16908 · Zoho · Manageengine Desktop Central

Published

2018-04-18

·

Updated

2019-10-03

·

CVE-2018-5340

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Desktop Central versions 10.0.124 through 10.0.184
Description An issue was discovered that allows database access using a superuser account, specifically an account with permission to write to the filesystem via SQL queries.
Recommendations For versions 10.0.124 through 10.0.184, consider restricting superuser account permissions to prevent unauthorized database access and filesystem modifications until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-5340

Affected Products

Manageengine Desktop Central