8.8

CVE-2021-40173

Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Cloud Security Plus Version4.1 Update4100
ZohocorpManageengine Cloud Security Plus Version4.1 Update4101
ZohocorpManageengine Cloud Security Plus Version4.1 Update4102
ZohocorpManageengine Cloud Security Plus Version4.1 Update4103
ZohocorpManageengine Cloud Security Plus Version4.1 Update4104
ZohocorpManageengine Cloud Security Plus Version4.1 Update4105
ZohocorpManageengine Cloud Security Plus Version4.1 Update4106
ZohocorpManageengine Cloud Security Plus Version4.1 Update4107
ZohocorpManageengine Cloud Security Plus Version4.1 Update4108
ZohocorpManageengine Cloud Security Plus Version4.1 Update4109
ZohocorpManageengine Cloud Security Plus Version4.1 Update4110
ZohocorpManageengine Cloud Security Plus Version4.1 Update4111
ZohocorpManageengine Cloud Security Plus Version4.1 Update4112
ZohocorpManageengine Cloud Security Plus Version4.1 Update4113
ZohocorpManageengine Cloud Security Plus Version4.1 Update4115
ZohocorpManageengine Cloud Security Plus Version4.1 Update4116
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.58% 0.661
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.