CRITICAL
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys
Published Feb 19, 2018
9.8
CRITICALCVSS 3.0
EPSS 8.60%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.