8.8
CWE
352
Advisory Published
Updated

CVE-2021-40173: CSRF

First published: Sun Aug 29 2021(Updated: )

Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Zohocorp Manageengine Cloud Security Plus<=4.0
Zohocorp Manageengine Cloud Security Plus=4.1-4100
Zohocorp Manageengine Cloud Security Plus=4.1-4101
Zohocorp Manageengine Cloud Security Plus=4.1-4102
Zohocorp Manageengine Cloud Security Plus=4.1-4103
Zohocorp Manageengine Cloud Security Plus=4.1-4104
Zohocorp Manageengine Cloud Security Plus=4.1-4105
Zohocorp Manageengine Cloud Security Plus=4.1-4106
Zohocorp Manageengine Cloud Security Plus=4.1-4107
Zohocorp Manageengine Cloud Security Plus=4.1-4108
Zohocorp Manageengine Cloud Security Plus=4.1-4109
Zohocorp Manageengine Cloud Security Plus=4.1-4110
Zohocorp Manageengine Cloud Security Plus=4.1-4111
Zohocorp Manageengine Cloud Security Plus=4.1-4112
Zohocorp Manageengine Cloud Security Plus=4.1-4113
Zohocorp Manageengine Cloud Security Plus=4.1-4115
Zohocorp Manageengine Cloud Security Plus=4.1-4116

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2021-40173?

    CVE-2021-40173 is a vulnerability in Zoho ManageEngine Cloud Security Plus before Build 4117 that allows a CSRF attack on the server proxy settings.

  • Which software versions are affected by CVE-2021-40173?

    CVE-2021-40173 affects Zoho ManageEngine Cloud Security Plus versions 4.0 up to and including 4.1-4116.

  • What is the severity of CVE-2021-40173?

    CVE-2021-40173 has a severity rating of 8.8 (high severity).

  • How can I fix CVE-2021-40173?

    To fix CVE-2021-40173, you should update Zoho ManageEngine Cloud Security Plus to build 4117 or later. Make sure to check the official release notes for the update process.

  • Where can I find more information about CVE-2021-40173?

    More information about CVE-2021-40173 can be found in the release notes of Zoho ManageEngine Cloud Security Plus.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203