#VU27564 Arbitrary file upload in Zoho ManageEngine Desktop Central - CVE-2020-10859
Published: May 6, 2020 / Updated: May 7, 2020
Zoho ManageEngine Desktop Central
Zoho Corporation
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload in ZIP decompressing portion within the Windows app dependency file upload functionality. A remote authenticated attacker can upload a malicious ZIP file with malicious path and execute it on the server.