CVE-2021-40173

Severity
8.8HIGH
EPSS
0.6%
top 31.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 24

Description

Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-pgx3-96qh-rj6x: Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings2022-05-24
CVEList
CVE-2021-40173: Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings2021-08-29
CVE-2021-40173 (HIGH CVSS 8.8) | Zoho ManageEngine Cloud Security Pl | cvebase.io