Skip to content

Latest commit

 

History

History

CVE-2020-10189

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

CVE-2020-10189 Zoho ManageEngine Desktop Central 10 getChartImage rce

Zoho ManageEngine Desktop Central 10 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

FOFA query rule: app="Zoho-ManageEngine-Desktop"

Demo