CVE-2021-44650

HIGH

Zoho ManageEngine M365 Manager Plus <Build 4419 - Command Injection

Title source: llm
STIX 2.1

Description

Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0461
EPSS Percentile 89.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
zohocorp/manageengine_m365_manager_plus 4.4 (17 CPE variants)
zohocorp/manageengine_m365_manager_plus < 4.4
Published Jan 12, 2022
Tracked Since Feb 18, 2026