Filtered by vendor Zohocorp
Subscribe
Total
511 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-12252 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2023-03-01 | 4.0 MEDIUM | 6.5 MEDIUM |
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring. | |||||
CVE-2019-12597 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-03-01 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName. | |||||
CVE-2019-12537 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-03-01 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field. | |||||
CVE-2019-12596 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-03-01 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType. | |||||
CVE-2019-12595 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-03-01 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter. | |||||
CVE-2019-19774 | 1 Zohocorp | 1 Manageengine Eventlog Analyzer | 2023-02-15 | 4.0 MEDIUM | 8.8 HIGH |
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5 hashes of the accounts used to authenticate the ManageEngine platform to the managed machines on the network (most often administrative accounts). Specifically, this bypasses these restrictions: a query cannot mention password, and a query result cannot have a password column. | |||||
CVE-2019-19034 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-02-03 | 6.5 MEDIUM | 7.2 HIGH |
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges. | |||||
CVE-2019-15510 | 1 Zohocorp | 1 Manageengine Desktop Central | 2023-02-03 | 4.3 MEDIUM | 6.1 MEDIUM |
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role. | |||||
CVE-2019-19649 | 1 Zohocorp | 1 Manageengine Applications Manager | 2023-02-02 | 7.5 HIGH | 9.8 CRITICAL |
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function. | |||||
CVE-2019-19475 | 1 Zohocorp | 1 Manageengine Applications Manager | 2023-02-01 | 9.0 HIGH | 8.8 HIGH |
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL configuration to execute arbitrary command to escalate and gain full system privilege user access and rights over the system. | |||||
CVE-2014-6038 | 1 Zohocorp | 1 Manageengine Eventlog Analyzer | 2023-02-01 | 5.0 MEDIUM | 7.5 HIGH |
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000. | |||||
CVE-2019-19650 | 1 Zohocorp | 1 Manageengine Applications Manager | 2023-01-30 | 6.5 MEDIUM | 8.8 HIGH |
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function. | |||||
CVE-2022-41978 | 1 Zohocorp | 1 Zoho Crm Lead Magnet | 2022-11-09 | N/A | 6.5 MEDIUM |
Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress. | |||||
CVE-2022-28219 | 1 Zohocorp | 1 Manageengine Adaudit Plus | 2022-10-26 | 7.5 HIGH | 9.8 CRITICAL |
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. | |||||
CVE-2022-25373 | 1 Zohocorp | 1 Manageengine Supportcenter Plus | 2022-10-07 | 3.5 LOW | 5.4 MEDIUM |
Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history. | |||||
CVE-2020-8838 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2022-10-07 | 4.9 MEDIUM | 6.4 MEDIUM |
An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack. | |||||
CVE-2020-27733 | 1 Zohocorp | 1 Manageengine Applications Manager | 2022-10-07 | 6.5 MEDIUM | 8.8 HIGH |
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request. | |||||
CVE-2020-9346 | 1 Zohocorp | 1 Manageengine Password Manager Pro | 2022-10-07 | 6.8 MEDIUM | 8.8 HIGH |
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role. | |||||
CVE-2022-24681 | 1 Zohocorp | 1 Manageengine Adselfservice Plus | 2022-10-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen. | |||||
CVE-2020-11946 | 1 Zohocorp | 1 Manageengine Opmanager | 2022-10-05 | 5.0 MEDIUM | 7.5 HIGH |
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. |