VYPR
Unrated severityCISA KEVNVD Advisory· Published Mar 6, 2020· Updated Oct 21, 2025

CVE-2020-10189

CVE-2020-10189

Description

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

Affected products

1
  • Zoho/ManageEngine Desktop Centraldescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.