CVE-2021-44651: Malicious File Upload
Published Jan 12, 2022
·Updated
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
Affected Software
10 affected components
ZohoCorp Manageengine Cloud Security Plus<4.1
ZohoCorp Manageengine Cloud Security Plus=4.1
ZohoCorp Manageengine Cloud Security Plus=4.1-build4110
ZohoCorp Manageengine Cloud Security Plus=4.1-build4111
ZohoCorp Manageengine Cloud Security Plus=4.1-build4112
ZohoCorp Manageengine Cloud Security Plus=4.1-build4113
ZohoCorp Manageengine Cloud Security Plus=4.1-build4115
ZohoCorp Manageengine Cloud Security Plus=4.1-build4116
ZohoCorp Log360<=5.2.2
ZohoCorp Manageengine Cloud Security Plus<=4.1.1.7
Event History
Jan 12, 2022
CVE Published
via MITRE·02:44 PM
Data Sourced
via MITRE·02:44 PM
Description
Frequently Asked Questions
1
What is CVE-2021-44651?
CVE-2021-44651 is a vulnerability in Zoho ManageEngine CloudSecurityPlus before Build 4117 that allows remote code execution.
2
How severe is CVE-2021-44651?
CVE-2021-44651 has a severity rating of 8.8 (high).
3
Which component of Zoho ManageEngine CloudSecurityPlus is affected by CVE-2021-44651?
The updatePersonalizeSettings component of Zoho ManageEngine CloudSecurityPlus is affected by CVE-2021-44651.
4
How can CVE-2021-44651 be exploited?
CVE-2021-44651 can be exploited through remote code execution.
5
Is there a fix for CVE-2021-44651?
Yes, CVE-2021-44651 can be fixed by updating to Build 4117 of Zoho ManageEngine CloudSecurityPlus.