CVE-2014-9331

ZOHO ManageEngine Desktop Central <9 - CSRF

Title source: llm

Description

Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do.

Exploits (1)

exploitdb WORKING POC
by Mohamed Idris · htmlwebappsmultiple
https://www.exploit-db.com/exploits/35980

Scores

EPSS 0.0205
EPSS Percentile 83.9%

Details

CWE
CWE-352
Status published
Products (1)
zohocorp/manageengine_desktop_central < 9.0
Published Feb 04, 2015
Tracked Since Feb 18, 2026