Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_cloud_security_plus | Zohocorp | * | 4.0 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4100 (including) | 4.1-4100 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4101 (including) | 4.1-4101 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4102 (including) | 4.1-4102 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4103 (including) | 4.1-4103 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4104 (including) | 4.1-4104 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4105 (including) | 4.1-4105 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4106 (including) | 4.1-4106 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4107 (including) | 4.1-4107 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4108 (including) | 4.1-4108 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4109 (including) | 4.1-4109 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4110 (including) | 4.1-4110 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4111 (including) | 4.1-4111 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4112 (including) | 4.1-4112 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4113 (including) | 4.1-4113 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4115 (including) | 4.1-4115 (including) |
Manageengine_cloud_security_plus | Zohocorp | 4.1-4116 (including) | 4.1-4116 (including) |