First published: Sun Aug 29 2021(Updated: )
Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Log360 | <=5.1 | |
Zohocorp Manageengine Log360 | =5.2-build5200 | |
Zohocorp Manageengine Log360 | =5.2-build5201 | |
Zohocorp Manageengine Log360 | =5.2-build5206 | |
Zohocorp Manageengine Log360 | =5.2-build5209 | |
Zohocorp Manageengine Log360 | =5.2-build5210 | |
Zohocorp Manageengine Log360 | =5.2-build5211 | |
Zohocorp Manageengine Log360 | =5.2-build5213 | |
Zohocorp Manageengine Log360 | =5.2-build5214 | |
Zohocorp Manageengine Log360 | =5.2-build5218 | |
Zohocorp Manageengine Log360 | =5.2-build5219 | |
Zohocorp Manageengine Log360 | =5.2-build5220_beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40174 is a vulnerability in Zoho ManageEngine Log360 before Build 5224 that allows a CSRF attack for disabling the logon security settings.
CVE-2021-40174 has a severity of 8.8 (high).
Zoho ManageEngine Log360 versions 5.1 up to 5.2-build5220_beta are affected by CVE-2021-40174.
CVE-2021-40174 can be exploited through a CSRF attack to disable the logon security settings.
Yes, a fix for CVE-2021-40174 is available in Build 5224 of Zoho ManageEngine Log360. Please refer to the official documentation for more information.