CVE-2021-40176: XSS
Published Aug 29, 2021
·Updated
Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
Affected Software
13 affected components
Zohocorp ManageEngine Log360<=5.1
Zohocorp ManageEngine Log360=5.2-build5200
Zohocorp ManageEngine Log360=5.2-build5201
Zohocorp ManageEngine Log360=5.2-build5206
Zohocorp ManageEngine Log360=5.2-build5209
Zohocorp ManageEngine Log360=5.2-build5210
Zohocorp ManageEngine Log360=5.2-build5211
Zohocorp ManageEngine Log360=5.2-build5213
Zohocorp ManageEngine Log360=5.2-build5214
Zohocorp ManageEngine Log360=5.2-build5218
Zohocorp ManageEngine Log360=5.2-build5219
Zohocorp ManageEngine Log360=5.2-build5220_beta
Zohocorp ManageEngine Log360=5.2-build5224
Event History
Aug 29, 2021
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-40176?
The severity of CVE-2021-40176 is medium with a CVSS score of 6.1.
2
How does CVE-2021-40176 affect Zoho ManageEngine Log360?
CVE-2021-40176 allows stored XSS in Zoho ManageEngine Log360 before Build 5225.
3
How can I fix CVE-2021-40176?
To fix CVE-2021-40176, upgrade to Zoho ManageEngine Log360 Build 5225 or later.
4
What is the affected software of CVE-2021-40176?
The affected software of CVE-2021-40176 is Zoho ManageEngine Log360 versions up to 5.1 and versions 5.2 through Build 5224.
5
Where can I find more information about CVE-2021-40176?
More information about CVE-2021-40176 can be found at the following link: https://www.manageengine.com/log-management/readme.html#Build%205225