Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGOPATH key value in the logon settings.