VYPR
Unrated severityNVD Advisory· Published Apr 18, 2018· Updated Aug 5, 2024

CVE-2018-5341

CVE-2018-5341

Description

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184 lack server-side file type validation when uploading and modifying scripts, allowing unauthenticated file upload and execution.

Vulnerability

Zoho ManageEngine Desktop Central versions 10.0.124 and 10.0.184 are affected by a missing server-side check on the file type or extension when uploading and modifying scripts. The vulnerability allows unauthenticated users to bypass file type restrictions, potentially enabling the upload of arbitrary web executables throughout the network [1].

Exploitation

An unauthenticated attacker can supply a specially crafted file, such as a web executable, during the script upload or modification process. Because the server does not validate the file type or extension, the attacker can place malicious files in locations that are later executed by the server or other clients. The attack requires network access to the Desktop Central console but does not require prior authentication [1].

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary web executables across the network, leading to remote code execution (RCE) as a privileged user. This compromises the confidentiality, integrity, and availability of the affected server and potentially all endpoints managed by it [1].

Mitigation

The vulnerability was fixed in a build released on 27-March-2018, as part of a cumulative update provided by Zoho. Administrators should update to the latest build of ManageEngine Desktop Central, available through the console's built-in update mechanism. No workaround is documented; updating is the only recommended mitigation. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.