VYPR

Log360

by Manageengine

CVEs (7)

  • CVE-2021-20136CriNov 1, 2021
    risk 0.65cvss 9.8epss 0.11

    ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled…

  • CVE-2021-40177CriAug 29, 2021
    risk 0.64cvss 9.8epss 0.05

    Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.

  • CVE-2021-40175CriAug 29, 2021
    risk 0.64cvss 9.8epss 0.07

    Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.

  • CVE-2021-40174HigAug 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.

  • CVE-2021-40172HigAug 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.

  • CVE-2021-40178MedAug 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.

  • CVE-2021-40176MedAug 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine Log360 before Build 5225 allows stored XSS.