CVE-2021-40178
29.08.2021, 20:15
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_log360 | 𝑥 ≤ 5.1 |
| zohocorp | manageengine_log360 | 5.2:build5200 |
| zohocorp | manageengine_log360 | 5.2:build5201 |
| zohocorp | manageengine_log360 | 5.2:build5206 |
| zohocorp | manageengine_log360 | 5.2:build5209 |
| zohocorp | manageengine_log360 | 5.2:build5210 |
| zohocorp | manageengine_log360 | 5.2:build5211 |
| zohocorp | manageengine_log360 | 5.2:build5213 |
| zohocorp | manageengine_log360 | 5.2:build5214 |
| zohocorp | manageengine_log360 | 5.2:build5218 |
| zohocorp | manageengine_log360 | 5.2:build5219 |
| zohocorp | manageengine_log360 | 5.2:build5220_beta |
𝑥
= Vulnerable software versions