RULE(RULE ID:324176)

Rule General Information
Release Date: 2020-01-20
Rule Name: ZOHO ManageEngine Desktop Central Unauthentication Database Query Vulnerability (CVE-2018-5338)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://www.manageengine.com/products/desktop-central/elevation-of-privilege-vulnerability.html
https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-manageengine-desktop-central/
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.manageengine.com/