ManageEngine Desktop Central MSP
by Zoho
CVEs (24)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46166 | Med | 0.42 | 6.5 | 0.03 | Jan 10, 2022 | Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page. | ||
| CVE-2019-15510 | Med | 0.40 | 6.1 | 0.03 | Mar 23, 2020 | ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role. | ||
| CVE-2022-23779 | Med | 0.36 | 5.3 | 0.15 | Mar 2, 2022 | Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses. | ||
| CVE-2019-16962 | Med | 0.35 | 5.4 | 0.02 | Jan 6, 2021 | Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report. |
- risk 0.42cvss 6.5epss 0.03
Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.
- risk 0.40cvss 6.1epss 0.03
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
- risk 0.36cvss 5.3epss 0.15
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.
- risk 0.35cvss 5.4epss 0.02
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
Page 2 of 2