CVE-2020-10859: Zohocorp ManageEngine Desktop Central

Medium severity, CVSS 6.5. EPSS: 4.4% chance of exploitation in the next 30 days.

Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request.

Affected products

  • Zohocorp ManageEngine Desktop Central: before 10.0.484 (fixed in 10.0.484)

Published 2020-05-05. Last modified 2026-06-17.