Vulnerabilities (CVE)

Filtered by vendor Zohocorp Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37919 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37918 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37762 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.
CVE-2021-37922 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 5.0 MEDIUM 5.3 MEDIUM
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.
CVE-2021-37926 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37921 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37920 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37924 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37923 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37930 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37929 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37928 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-37931 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVE-2021-38298 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
CVE-2021-33849 1 Zohocorp 1 Zoho Crm Lead Magnet 2021-10-14 3.5 LOW 5.4 MEDIUM
A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever the user changes the form values or deletes a created form in Zoho CRM Lead Magnet Version 1.7.2.4.
CVE-2021-41288 1 Zohocorp 1 Manageengine Opmanager 2021-10-07 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
CVE-2021-41828 1 Zohocorp 1 Manageengine Remote Access Plus 2021-10-05 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
CVE-2021-41827 1 Zohocorp 1 Manageengine Remote Access Plus 2021-10-05 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.
CVE-2021-37761 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-01 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.
CVE-2021-37539 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-01 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
CVE-2021-37925 1 Zohocorp 1 Manageengine Admanager Plus 2021-09-29 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
CVE-2020-28653 1 Zohocorp 1 Manageengine Opmanager 2021-09-22 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
CVE-2021-3287 1 Zohocorp 1 Manageengine Opmanager 2021-09-22 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.
CVE-2021-33256 1 Zohocorp 1 Manageengine Adselfservice Plus 2021-09-21 9.3 HIGH 8.8 HIGH
** DISPUTED ** A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side."
CVE-2021-31530 1 Zohocorp 1 Manageengine Servicedesk Plus Msp 2021-09-21 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.
CVE-2021-31813 1 Zohocorp 1 Manageengine Applications Manager 2021-09-21 3.5 LOW 5.4 MEDIUM
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
CVE-2021-37423 1 Zohocorp 1 Manageengine Adselfservice Plus 2021-09-17 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.
CVE-2021-37422 1 Zohocorp 1 Manageengine Adselfservice Plus 2021-09-17 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
CVE-2021-33055 2 Microsoft, Zohocorp 2 Windows, Manageengine Adselfservice Plus 2021-09-02 10.0 HIGH 9.8 CRITICAL
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
CVE-2021-37416 1 Zohocorp 1 Manageengine Adselfservice Plus 2021-09-02 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
CVE-2021-40178 1 Zohocorp 1 Manageengine Log360 2021-09-01 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
CVE-2021-40175 1 Zohocorp 1 Manageengine Log360 2021-09-01 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.
CVE-2021-40174 1 Zohocorp 1 Manageengine Log360 2021-09-01 6.8 MEDIUM 8.8 HIGH
Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
CVE-2021-40173 1 Zohocorp 1 Manageengine Cloud Security Plus 2021-09-01 6.8 MEDIUM 8.8 HIGH
Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.
CVE-2021-40177 1 Zohocorp 1 Manageengine Log360 2021-09-01 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
CVE-2021-40176 1 Zohocorp 1 Manageengine Log360 2021-09-01 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
CVE-2021-40172 1 Zohocorp 1 Manageengine Log360 2021-09-01 6.8 MEDIUM 8.8 HIGH
Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.
CVE-2021-33617 1 Zohocorp 1 Manageengine Password Manager Pro 2021-08-10 5.0 MEDIUM 5.3 MEDIUM
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.
CVE-2021-36772 1 Zohocorp 1 Manageengine Admanager Plus 2021-07-28 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
CVE-2021-36771 1 Zohocorp 1 Manageengine Admanager Plus 2021-07-28 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
CVE-2021-20110 1 Zohocorp 1 Manageengine Assetexplorer 2021-07-28 10.0 HIGH 9.8 CRITICAL
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request verifying its authtoken. In httphandler.cpp, the agent reaching out over HTTP is vulnerable to an Integer Overflow, which can be turned into a Heap Overflow allowing for remote code execution as NT AUTHORITY/SYSTEM on the agent machine. The Integer Overflow occurs when receiving POST response from the Manage Engine server, and the agent calling "HttpQueryInfoW" in order to get the "Content-Length" size from the incoming POST request. This size is taken, but multiplied to a larger amount. If an attacker specifies a Content-Length size of 1073741823 or larger, this integer arithmetic will wrap the value back around to smaller integer, then calls "calloc" with this size to allocate memory. The following API "InternetReadFile" will copy the POST data into this buffer, which will be too small for the contents, and cause heap overflow.
CVE-2021-20109 1 Zohocorp 1 Manageengine Assetexplorer 2021-07-28 5.0 MEDIUM 7.5 HIGH
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request verifying its authtoken. In AEAgent.cpp, the agent responding back over HTTP is vulnerable to a Heap Overflow if the POST payload response is too large. The POST payload response is converted to Unicode using vswprintf. This is written to a buffer only 0x2000 bytes big. If POST payload is larger, then heap overflow will occur.
CVE-2021-20108 1 Zohocorp 1 Manageengine Assetexplorer 2021-07-28 5.0 MEDIUM 7.5 HIGH
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these commands may not be executed (due to authtoken validation), the Asset Explorer agent will reach out to the manage engine server for an HTTP request. During this process, AEAgent.cpp allocates 0x66 bytes using "malloc". This memory is never free-ed in the program, causing a memory leak. Additionally, the instruction sent to aeagent (ie: NEWSCAN, DELTASCAN, etc) is converted to a unicode string, but is never freed. These memory leaks allow a remote attacker to exploit a Denial of Service scenario through repetitively sending these commands to an agent and eventually crashing it the agent due to an out-of-memory condition.
CVE-2020-11527 1 Zohocorp 1 Manageengine Opmanager 2021-07-21 5.0 MEDIUM 7.5 HIGH
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
CVE-2020-12116 1 Zohocorp 1 Manageengine Opmanager 2021-07-21 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
CVE-2020-10541 1 Zohocorp 1 Manageengine Opmanager 2021-07-21 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
CVE-2020-29658 1 Zohocorp 1 Manageengine Applications Control Plus 2021-07-21 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.
CVE-2020-13154 1 Zohocorp 1 Manageengine Servicedesk Plus 2021-07-21 4.0 MEDIUM 6.5 MEDIUM
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
CVE-2020-8509 1 Zohocorp 1 Manageengine Desktop Central 2021-07-21 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
CVE-2019-19800 1 Zohocorp 1 Manageengine Applications Manager 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.