Loading
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
Use CWE-502, Zohocorp vendor hub and Manageengine Desktop Central product page to widen CVE-2020-10189 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-44515, CVE-2021-44757 and CVE-2022-48362 for nearby disclosures in the same product family.