Vulnerabilities > Zohocorp > High

DATE CVE VULNERABILITY TITLE RISK
2021-08-29 CVE-2021-40172 Cross-Site Request Forgery (CSRF) vulnerability in Zohocorp Manageengine Log360 5.0/5.1/5.2
Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.
network
low complexity
zohocorp CWE-352
8.8
2021-08-29 CVE-2021-40173 Cross-Site Request Forgery (CSRF) vulnerability in Zohocorp Manageengine Cloud Security Plus 4.0/4.1
Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.
network
low complexity
zohocorp CWE-352
8.8
2021-08-29 CVE-2021-40174 Cross-Site Request Forgery (CSRF) vulnerability in Zohocorp Manageengine Log360 5.0/5.1/5.2
Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
network
low complexity
zohocorp CWE-352
8.8
2021-08-09 CVE-2021-33256 Improper Neutralization of Formula Elements in a CSV File vulnerability in Zohocorp Manageengine Adselfservice Plus 6.1
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user.
network
low complexity
zohocorp CWE-1236
8.8
2021-07-19 CVE-2021-20108 Memory Leak vulnerability in Zohocorp Manageengine Assetexplorer 1.0.34
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server.
network
low complexity
zohocorp CWE-401
7.5
2021-07-19 CVE-2021-20109 Out-of-bounds Write vulnerability in Zohocorp Manageengine Assetexplorer 1.0.34
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address.
network
low complexity
zohocorp CWE-787
7.5
2021-06-29 CVE-2021-31160 Unspecified vulnerability in Zohocorp products
Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.
network
low complexity
zohocorp
7.5
2021-06-29 CVE-2021-31530 Unspecified vulnerability in Zohocorp Manageengine Servicedesk Plus MSP 10.5
Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.
network
low complexity
zohocorp
7.5
2021-06-10 CVE-2021-20081 Unspecified vulnerability in Zohocorp Manageengine Servicedesk Plus
Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
network
low complexity
zohocorp
7.2
2021-03-18 CVE-2020-9367 Uncontrolled Search Path Element vulnerability in Zohocorp Manageengine Desktop Central 10.0.486
The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path.
local
low complexity
zohocorp CWE-427
7.8