CVE-2021-31813
- EPSS 78.27%
- Veröffentlicht 01.07.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:16
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
CVE-2020-35765
- EPSS 27.35%
- Veröffentlicht 05.02.2021 14:15:16
- Zuletzt bearbeitet 21.11.2024 05:28:02
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
CVE-2020-27733
- EPSS 8.81%
- Veröffentlicht 19.01.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:42
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
CVE-2020-27995
- EPSS 8.83%
- Veröffentlicht 29.10.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:22:10
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
CVE-2020-10816
- EPSS 4.85%
- Veröffentlicht 08.10.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:07
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
CVE-2020-16267
- EPSS 43.33%
- Veröffentlicht 06.10.2020 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:07:03
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
CVE-2020-15927
- EPSS 43.33%
- Veröffentlicht 06.10.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:28
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
CVE-2020-15533
- EPSS 4.2%
- Veröffentlicht 01.10.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:42
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
CVE-2020-15521
- EPSS 1.69%
- Veröffentlicht 25.09.2020 07:15:11
- Zuletzt bearbeitet 21.11.2024 05:05:41
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
CVE-2020-15394
- EPSS 7.87%
- Veröffentlicht 25.09.2020 07:15:11
- Zuletzt bearbeitet 21.11.2024 05:05:28
The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.