Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-06T16:05:22.000Z
Updated: 2025-07-30T01:45:47.214Z
Reserved: 2020-03-06T00:00:00.000Z
Link: CVE-2020-10189
Updated: 2024-08-04T10:58:39.095Z
Status : Analyzed
Published: 2020-03-06T17:15:12.383
Modified: 2025-03-14T17:41:12.670
Link: CVE-2020-10189
No data.