Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_log360 | Zohocorp | * | 5.1 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5200 (including) | 5.2-build5200 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5201 (including) | 5.2-build5201 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5206 (including) | 5.2-build5206 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5209 (including) | 5.2-build5209 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5210 (including) | 5.2-build5210 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5211 (including) | 5.2-build5211 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5213 (including) | 5.2-build5213 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5214 (including) | 5.2-build5214 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5218 (including) | 5.2-build5218 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5219 (including) | 5.2-build5219 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5220_beta (including) | 5.2-build5220_beta (including) |