CVE-2019-15510: Zohocorp ManageEngine Desktop Central

Medium severity, CVSS 6.1. EPSS: 3.2% chance of exploitation in the next 30 days.

ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.

Affected products

  • Zohocorp ManageEngine Desktop Central: version 10.0 only

Published 2020-03-23. Last modified 2026-06-17.