CVE-2021-46166

Severity
6.5MEDIUM
EPSS
0.3%
top 46.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 11

Description

Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-hqxq-qqh3-mqjg: Zoho ManageEngine Desktop Central before 102022-01-11
CVEList
CVE-2021-46166: Zoho ManageEngine Desktop Central before 102022-01-09
CVE-2021-46166 (MEDIUM CVSS 6.5) | Zoho ManageEngine Desktop Central b | cvebase.io