CVE-2021-40172: CSRF
Published Aug 29, 2021
·Updated
Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.
Affected Software
10 affected components
Zohocorp ManageEngine Log360>=5.0<=5.1
Zohocorp ManageEngine Log360=5.2-build5200
Zohocorp ManageEngine Log360=5.2-build5201
Zohocorp ManageEngine Log360=5.2-build5206
Zohocorp ManageEngine Log360=5.2-build5209
Zohocorp ManageEngine Log360=5.2-build5210
Zohocorp ManageEngine Log360=5.2-build5211
Zohocorp ManageEngine Log360=5.2-build5213
Zohocorp ManageEngine Log360=5.2-build5214
Zohocorp ManageEngine Log360=5.2-build5218
Event History
Aug 29, 2021
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-40172?
CVE-2021-40172 is a vulnerability in Zoho ManageEngine Log360 before Build 5219 that allows a CSRF attack on proxy settings.
2
How severe is CVE-2021-40172?
CVE-2021-40172 is classified as a high severity vulnerability with a CVSS score of 8.8.
3
Which software versions of Zoho ManageEngine Log360 are affected by CVE-2021-40172?
The affected software versions of Zoho ManageEngine Log360 are 5.0 to 5.1, 5.2-build5200, 5.2-build5201, 5.2-build5206, 5.2-build5209, 5.2-build5210, 5.2-build5211, 5.2-build5213, and 5.2-build5214.
4
How can I fix CVE-2021-40172?
To fix CVE-2021-40172, it is recommended to update Zoho ManageEngine Log360 to Build 5219 or later. More details on the fix can be found at [link].
5
What is the Common Weakness Enumeration (CWE) for CVE-2021-40172?
The CWE for CVE-2021-40172 is CWE-352.