CVE-2021-40173

Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
zohocorpmanageengine_cloud_security_plus
𝑥
≤ 4.0
zohocorpmanageengine_cloud_security_plus
4.1:4100
zohocorpmanageengine_cloud_security_plus
4.1:4101
zohocorpmanageengine_cloud_security_plus
4.1:4102
zohocorpmanageengine_cloud_security_plus
4.1:4103
zohocorpmanageengine_cloud_security_plus
4.1:4104
zohocorpmanageengine_cloud_security_plus
4.1:4105
zohocorpmanageengine_cloud_security_plus
4.1:4106
zohocorpmanageengine_cloud_security_plus
4.1:4107
zohocorpmanageengine_cloud_security_plus
4.1:4108
zohocorpmanageengine_cloud_security_plus
4.1:4109
zohocorpmanageengine_cloud_security_plus
4.1:4110
zohocorpmanageengine_cloud_security_plus
4.1:4111
zohocorpmanageengine_cloud_security_plus
4.1:4112
zohocorpmanageengine_cloud_security_plus
4.1:4113
zohocorpmanageengine_cloud_security_plus
4.1:4115
zohocorpmanageengine_cloud_security_plus
4.1:4116
𝑥
= Vulnerable software versions