Stored XSS Vulnerability in Zoho ManageEngine Log360
CVE-2021-40178
6.1MEDIUM
What is CVE-2021-40178?
The vulnerability in Zoho ManageEngine Log360 allows attackers to exploit the stored cross-site scripting (XSS) flaw via the LOGO_PATH key value in the logon settings, potentially leading to execution of malicious scripts in the context of the user’s session. This can compromise sensitive data and affect user trust.