Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_log360 | Zohocorp | * | 5.1 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5200 (including) | 5.2-build5200 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5201 (including) | 5.2-build5201 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5206 (including) | 5.2-build5206 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5209 (including) | 5.2-build5209 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5210 (including) | 5.2-build5210 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5211 (including) | 5.2-build5211 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5213 (including) | 5.2-build5213 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5214 (including) | 5.2-build5214 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5218 (including) | 5.2-build5218 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5219 (including) | 5.2-build5219 (including) |
Manageengine_log360 | Zohocorp | 5.2-build5220_beta (including) | 5.2-build5220_beta (including) |