Learn about CVE-2021-40178, a stored XSS vulnerability in Zoho ManageEngine Log360 before Build 5224. Understand the impact, technical details, and mitigation steps.
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
Understanding CVE-2021-40178
Zoho ManageEngine Log360 before Build 5224 is susceptible to stored XSS due to a vulnerability in the LOGO_PATH key value.
What is CVE-2021-40178?
CVE-2021-40178 is a Common Vulnerabilities and Exposures (CVE) entry that highlights the stored cross-site scripting (XSS) issue in Zoho ManageEngine Log360 before Build 5224.
The Impact of CVE-2021-40178
This vulnerability allows attackers to execute malicious scripts in the context of a user's session, potentially leading to unauthorized data access or manipulation.
Technical Details of CVE-2021-40178
Zoho ManageEngine Log360 before Build 5224 is affected by the following technical details:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
It is crucial to take immediate steps to mitigate and prevent the impact of CVE-2021-40178:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates