CVE-2021-40174: CSRF
Published Aug 29, 2021
·Updated
Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
Affected Software
12 affected components
Zohocorp ManageEngine Log360<=5.1
Zohocorp ManageEngine Log360=5.2-build5200
Zohocorp ManageEngine Log360=5.2-build5201
Zohocorp ManageEngine Log360=5.2-build5206
Zohocorp ManageEngine Log360=5.2-build5209
Zohocorp ManageEngine Log360=5.2-build5210
Zohocorp ManageEngine Log360=5.2-build5211
Zohocorp ManageEngine Log360=5.2-build5213
Zohocorp ManageEngine Log360=5.2-build5214
Zohocorp ManageEngine Log360=5.2-build5218
Zohocorp ManageEngine Log360=5.2-build5219
Zohocorp ManageEngine Log360=5.2-build5220_beta
Event History
Aug 29, 2021
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-40174?
CVE-2021-40174 is a vulnerability in Zoho ManageEngine Log360 before Build 5224 that allows a CSRF attack for disabling the logon security settings.
2
What is the severity of CVE-2021-40174?
CVE-2021-40174 has a severity of 8.8 (high).
3
Which software products are affected by CVE-2021-40174?
Zoho ManageEngine Log360 versions 5.1 up to 5.2-build5220_beta are affected by CVE-2021-40174.
4
How can this vulnerability be exploited?
CVE-2021-40174 can be exploited through a CSRF attack to disable the logon security settings.
5
Is there a fix available for CVE-2021-40174?
Yes, a fix for CVE-2021-40174 is available in Build 5224 of Zoho ManageEngine Log360. Please refer to the official documentation for more information.