PT-2021-22832 · Zoho · Zoho Manageengine Log360

Published

2021-08-29

·

Updated

2021-09-01

·

CVE-2021-40174

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Log360 versions prior to Build 5224
Description The issue allows a CSRF attack for disabling the logon security settings.
Recommendations For versions prior to Build 5224, update to Build 5224 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to prevent CSRF attacks, such as validating request origins and using anti-CSRF tokens. Restrict access to the logon security settings to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40174

Affected Products

Zoho Manageengine Log360