Vulnerabilities in Zoho
4 resultsVexday analysis
Zoho apresenta um panorama de risco contido com apenas 3 vulnerabilidades registradas, nenhuma delas sob exploração ativa ou classificada como crítica. A fraqueza dominante identificada é path traversal (CWE-22), representando um risco de acesso não autorizado a arquivos, mas sem indicadores recentes de atividade maliciosa, sugerindo uma postura de segurança estável no período analisado.
CVE-2017-11512—The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the namEPSS 52.5%CVE-2016-1159—In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive informatiEPSS 4.4%CVE-2017-11511—The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filEPSS 3.4%CVE-2021-33849—A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a truEPSS 1.1%