Filtered by vendor Zohocorp
Subscribe
Total
418 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-48362 | 1 Zohocorp | 1 Manageengine Desktop Central | 2023-03-14 | N/A | 8.8 HIGH |
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.) | |||||
CVE-2023-26600 | 1 Zohocorp | 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more | 2023-03-13 | N/A | 6.5 MEDIUM |
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports. | |||||
CVE-2023-26601 | 1 Zohocorp | 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more | 2023-03-13 | N/A | 7.5 HIGH |
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS). | |||||
CVE-2019-12252 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2023-03-01 | 4.0 MEDIUM | 6.5 MEDIUM |
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring. | |||||
CVE-2019-12597 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-03-01 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName. | |||||
CVE-2019-12595 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-03-01 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter. | |||||
CVE-2019-12596 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-03-01 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType. | |||||
CVE-2019-12537 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-03-01 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field. | |||||
CVE-2023-23076 | 1 Zohocorp | 1 Manageengine Supportcenter Plus | 2023-02-22 | N/A | 9.8 CRITICAL |
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. | |||||
CVE-2023-23077 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2023-02-22 | N/A | 6.1 MEDIUM |
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment. | |||||
CVE-2023-23078 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2023-02-22 | N/A | 6.1 MEDIUM |
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets. | |||||
CVE-2021-41081 | 1 Zohocorp | 1 Manageengine Network Configuration Manager | 2023-02-22 | 7.5 HIGH | 9.8 CRITICAL |
Zoho ManageEngine Network Configuration Manager before ??125465 is vulnerable to SQL Injection in a configuration search. | |||||
CVE-2021-41080 | 1 Zohocorp | 1 Manageengine Network Configuration Manager | 2023-02-22 | 7.5 HIGH | 9.8 CRITICAL |
Zoho ManageEngine Network Configuration Manager before ??125465 is vulnerable to SQL Injection in a hardware details search. | |||||
CVE-2023-0169 | 1 Zohocorp | 1 Zoho Forms | 2023-02-15 | N/A | 5.4 MEDIUM |
The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
CVE-2019-19774 | 1 Zohocorp | 1 Manageengine Eventlog Analyzer | 2023-02-14 | 4.0 MEDIUM | 8.8 HIGH |
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5 hashes of the accounts used to authenticate the ManageEngine platform to the managed machines on the network (most often administrative accounts). Specifically, this bypasses these restrictions: a query cannot mention password, and a query result cannot have a password column. | |||||
CVE-2023-23073 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2023-02-14 | N/A | 6.1 MEDIUM |
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component. | |||||
CVE-2023-23074 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2023-02-14 | N/A | 6.1 MEDIUM |
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component. | |||||
CVE-2022-47966 | 1 Zohocorp | 23 Application Control Plus, Manageengine Access Manager Plus, Manageengine Ad360 and 20 more | 2023-02-09 | N/A | 9.8 CRITICAL |
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. | |||||
CVE-2023-23075 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-02-08 | N/A | 6.1 MEDIUM |
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation. | |||||
CVE-2019-19034 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2023-02-03 | 6.5 MEDIUM | 7.2 HIGH |
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges. |