CVE-2019-15510
Zoho ManageEngine Desktop Central Server vulnerability analysis and mitigation

Overview

ManageEngine Desktop Central version 10 was found to be vulnerable to HTML injection (CVE-2019-15510). The vulnerability was discovered in the user administration pages where texts similar to HTML tags in user descriptions could create unwanted HTML injections, causing changes in the user data created (ManageEngine Doc).

Technical details

The vulnerability exists in the user administration interface where input validation was insufficient for user description fields. When creating or modifying user descriptions, the application failed to properly sanitize text that resembled HTML tags, allowing them to be interpreted and executed by the browser (ManageEngine Doc).

Impact

This vulnerability could allow attackers to inject arbitrary HTML code into vulnerable web pages. The potential consequences include disclosure of user session cookies that could be used for impersonation, or more broadly, allowing attackers to modify page content seen by victims. When exploited, the injected HTML would be rendered and executed in the victim's browser context within the trusted domain (ESec Forte).

Mitigation and workarounds

The vulnerability was identified and fixed by ManageEngine on November 4, 2019. Users should update their Desktop Central installation to the version containing the fix. The update can be applied by logging into the Desktop Central console and downloading the latest applicable build (ManageEngine Doc).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine Desktop Central Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-4769HIGH8.8
  • Zoho ManageEngine Desktop Central ServerZoho ManageEngine Desktop Central Server
  • cpe:2.3:a:zohocorp:manageengine_desktop_central
NoNoNov 03, 2023
CVE-2022-48362HIGH8.8
  • Zoho ManageEngine Desktop Central ServerZoho ManageEngine Desktop Central Server
  • cpe:2.3:a:zohocorp:manageengine_desktop_central
NoYesFeb 25, 2023
CVE-2023-4768MEDIUM6.1
  • Zoho ManageEngine Desktop Central ServerZoho ManageEngine Desktop Central Server
  • cpe:2.3:a:zohocorp:manageengine_desktop_central
NoNoNov 03, 2023
CVE-2023-4767MEDIUM6.1
  • Zoho ManageEngine Desktop Central ServerZoho ManageEngine Desktop Central Server
  • cpe:2.3:a:zohocorp:manageengine_desktop_central
NoNoNov 03, 2023
CVE-2022-23779MEDIUM5.3
  • Zoho ManageEngine Desktop Central ServerZoho ManageEngine Desktop Central Server
  • cpe:2.3:a:zohocorp:manageengine_desktop_central
NoYesMar 02, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management