CVE-2020-10859: Zohocorp ManageEngine Desktop Central
Medium severity, CVSS 6.5. EPSS: 4.4% chance of exploitation in the next 30 days.
Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request.
Affected products
- Zohocorp ManageEngine Desktop Central: before 10.0.484 (fixed in 10.0.484)
Published 2020-05-05. Last modified 2026-06-17.