Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
2022-01-12T15:15:07.360
2024-11-21T06:31:19.260
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zohocorp | manageengine_cloud_security_plus | < 4.1 | Yes |
Application | zohocorp | manageengine_cloud_security_plus | 4.1 | Yes |
Application | zohocorp | manageengine_cloud_security_plus | 4.1 | Yes |
Application | zohocorp | manageengine_cloud_security_plus | 4.1 | Yes |
Application | zohocorp | manageengine_cloud_security_plus | 4.1 | Yes |
Application | zohocorp | manageengine_cloud_security_plus | 4.1 | Yes |
Application | zohocorp | manageengine_cloud_security_plus | 4.1 | Yes |
Application | zohocorp | manageengine_cloud_security_plus | 4.1 | Yes |
Application | zohocorp | log360 | ≤ 5.2.2 | Yes |
Application | zohocorp | manageengine_cloud_security_plus | ≤ 4.1.1.7 | Yes |