Severity
7.5HIGH
EPSS
12.0%
top 6.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMay 24

Description

Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-w724-jhc8-5hm6: Zoho ManageEngine Desktop Central allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure2022-05-24
CVEList
CVE-2020-8509: Zoho ManageEngine Desktop Central before 102020-03-30
CVE-2020-8509 (HIGH CVSS 7.5) | Zoho ManageEngine Desktop Central b | cvebase.io