CVE-2015-8249 | Zoho ManageEngine Desktop Central 9 FileUploadServlet ConnectionId unrestricted upload (EDB-38982 / ID 802424)
A vulnerability, which was classified as critical, has been found in Zoho ManageEngine Desktop Central 9. Affected by this issue is the function FileUploadServlet. The manipulation of the argument ConnectionId as part of Parameter leads to unrestricted upload.
This vulnerability is handled as CVE-2015-8249. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.