Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_desktop_central | - | 10.1.2137.9 |
| zohocorp / manageengine_desktop_central_managed_service_providers | - | 10.1.2137.9 |