Loading vulnerability details…
CVSS v3.1
N/A
EPSS
81.05%
Published
Jan 4, 2018
Modified
Nov 20, 2024
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
Weaknesses (CWE)
Affected Products (2)
References (16)