Loading
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.)
Use CWE-22, Zohocorp vendor hub and Manageengine Desktop Central product page to widen CVE-2022-48362 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-44515, CVE-2021-44757 and CVE-2021-46164 for nearby disclosures in the same product family.