CVE-2022-23779
MEDIUM NUCLEIZohocorp Manageengine Desktop Central - Information Disclosure
Title source: ruleDescription
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.
Exploits (3)
Nuclei Templates (1)
Zoho ManageEngine - Internal Hostname Disclosure
MEDIUMby cckuailong
Shodan:
http.title:"manageengine desktop central 10"
FOFA:
app="ZOHO-ManageEngine-Desktop" || title="manageengine desktop central 10" || app="zoho-manageengine-desktop"
Scores
CVSS v3
5.3
EPSS
0.7918
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (1)
zohocorp/manageengine_desktop_central
< 10.1.2137.8
Published
Mar 02, 2022
Tracked Since
Feb 18, 2026