Show filters
52 Total Results
Displaying 1-10 of 52
Sort by:
Attacker Value
Unknown

CVE-2024-5678

Disclosure Date: August 01, 2024 (last updated August 16, 2024)
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
Attacker Value
Unknown

CVE-2023-38333

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
Attacker Value
Unknown

CVE-2023-29442

Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
Attacker Value
Unknown

CVE-2023-28341

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
Attacker Value
Unknown

CVE-2023-28340

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
Attacker Value
Unknown

CVE-2022-23050

Disclosure Date: May 24, 2022 (last updated October 07, 2023)
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
Attacker Value
Unknown

CVE-2020-28679

Disclosure Date: January 10, 2022 (last updated October 07, 2023)
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
Attacker Value
Unknown

CVE-2020-24743

Disclosure Date: November 03, 2021 (last updated November 29, 2024)
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
Attacker Value
Unknown

CVE-2021-35512

Disclosure Date: October 21, 2021 (last updated November 28, 2024)
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
Attacker Value
Unknown

CVE-2021-31813

Disclosure Date: July 01, 2021 (last updated February 22, 2025)
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.