CVE-2021-46166: Infoleak
Published Jan 9, 2022
·Updated
Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.
Affected Software
1 affected component
ZohoCorp Manageengine Desktop Central<10.0.662
Event History
Jan 9, 2022
CVE Published
via MITRE·12:25 AM
Data Sourced
via MITRE·12:25 AM
Description
Jan 10, 2022
Data Sourced
via NVD·02:11 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2021-46166.
2
What is the severity of CVE-2021-46166?
The severity of CVE-2021-46166 is medium with a severity value of 6.5.
3
How can authenticated users exploit CVE-2021-46166?
Authenticated users can exploit CVE-2021-46166 by visiting the Reports page and obtaining sensitive information from the database.
4
What is the affected software by CVE-2021-46166?
The affected software by CVE-2021-46166 is Zohocorp Manageengine Desktop Central version up to exclusive 10.0.662.
5
Is there a fix available for CVE-2021-46166?
Yes, a fix is available for CVE-2021-46166. Users should upgrade to Zohocorp Manageengine Desktop Central version 10.0.662 or higher.