CVE-2020-15594

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
30/09/2020
Last modified:
30/05/2025

Description

An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_application_control_plus:*:*:*:*:*:*:*:* 10.0.511 (excluding)