Vulnerability Details CVE-2022-48362
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 78.6%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-48362
-
cpe:2.3:a:zohocorp:manageengine_desktop_central:-
-
cpe:2.3:a:zohocorp:manageengine_desktop_central:10.0.137
-
cpe:2.3:a:zohocorp:manageengine_desktop_central:10.1.2127.17
-
cpe:2.3:a:zohocorp:manageengine_desktop_central:10.1.2127.18
-
cpe:2.3:a:zohocorp:manageengine_desktop_central:10.1.2128.0
-
cpe:2.3:a:zohocorp:manageengine_desktop_central:9.0