QID 375848
Date Published: 2021-09-21
QID 375848: Zoho ManageEngine Log360 Multiple Vulnerabilities
Zoho ManageEngine Log360 is an integrated solution that combines EventLog Analyzer, ADAudit Plus, and Cloud Security Plus into a single console to help manage network security, Active Directory auditing, and public cloud management.
Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
Affected Versions:
Zoho ManageEngine Log360 before Build 5225
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of Zoho ManageEngine Log360 by checking the build number in product.conf file.
Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code remotely
Vendor has released patch, download latest version of Zoho ManageEngine Log360 from here.
- Zoho Manageengine Log 360 Release Notes -
www.manageengine.com/log-management/readme.html#Build%205225
CVEs related to QID 375848
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|