VendorsZoho Corpmanageengine_desktop_central10.0.137
Vulnerabilities

Zoho Corp ZohoCorp ManageEngine Desktop Central 10.0.137

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2017-16924
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys. This is fixed in build 100157.
Published 2018-02-19 · Modified
9.8EPSS 0.086