CWE
79
Advisory Published
Updated

CVE-2021-20080: XSS

First published: Fri Apr 09 2021(Updated: )

Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.

Credit: vulnreport@tenable.com

Affected SoftwareAffected VersionHow to fix
ManageEngine ServiceDesk Plus=8.1
ManageEngine ServiceDesk Plus=8.2
ManageEngine ServiceDesk Plus=8.2-8201
ManageEngine ServiceDesk Plus=8.2-8202
ManageEngine ServiceDesk Plus=8.2-8203
ManageEngine ServiceDesk Plus=8.2-8204
ManageEngine ServiceDesk Plus=8.2-8205
ManageEngine ServiceDesk Plus=8.2-8206
ManageEngine ServiceDesk Plus=8.2-8207
ManageEngine ServiceDesk Plus=8.2-8208
ManageEngine ServiceDesk Plus=8.2-8209
ManageEngine ServiceDesk Plus=8.2-8210
ManageEngine ServiceDesk Plus=8.2-8211
ManageEngine ServiceDesk Plus=8.2-8212
ManageEngine ServiceDesk Plus=8.2-8213
ManageEngine ServiceDesk Plus=8.2-8214
ManageEngine ServiceDesk Plus=8.2-8215
ManageEngine ServiceDesk Plus=8.2-8216
ManageEngine ServiceDesk Plus=8.2-8217
ManageEngine ServiceDesk Plus=9.0
ManageEngine ServiceDesk Plus=9.0-9000
ManageEngine ServiceDesk Plus=9.0-9001
ManageEngine ServiceDesk Plus=9.0-9002
ManageEngine ServiceDesk Plus=9.0-9003
ManageEngine ServiceDesk Plus=9.0-9004
ManageEngine ServiceDesk Plus=9.0-9005
ManageEngine ServiceDesk Plus=9.0-9006
ManageEngine ServiceDesk Plus=9.0-9007
ManageEngine ServiceDesk Plus=9.0-9008
ManageEngine ServiceDesk Plus=9.0-9009
ManageEngine ServiceDesk Plus=9.0-9010
ManageEngine ServiceDesk Plus=9.0-9011
ManageEngine ServiceDesk Plus=9.0-9012
ManageEngine ServiceDesk Plus=9.0-9013
ManageEngine ServiceDesk Plus=9.0-9014
ManageEngine ServiceDesk Plus=9.0-9016
ManageEngine ServiceDesk Plus=9.0-9017
ManageEngine ServiceDesk Plus=9.0-9018
ManageEngine ServiceDesk Plus=9.0-9019
ManageEngine ServiceDesk Plus=9.0-9020
ManageEngine ServiceDesk Plus=9.0-9021
ManageEngine ServiceDesk Plus=9.0-9022
ManageEngine ServiceDesk Plus=9.0-9023
ManageEngine ServiceDesk Plus=9.0-9024
ManageEngine ServiceDesk Plus=9.0-9025
ManageEngine ServiceDesk Plus=9.0-9026
ManageEngine ServiceDesk Plus=9.0-9027
ManageEngine ServiceDesk Plus=9.0-9028
ManageEngine ServiceDesk Plus=9.0-9029
ManageEngine ServiceDesk Plus=9.0-9030
ManageEngine ServiceDesk Plus=9.0-9031
ManageEngine ServiceDesk Plus=9.0-9032
ManageEngine ServiceDesk Plus=9.0-9033
ManageEngine ServiceDesk Plus=9.0-9034
ManageEngine ServiceDesk Plus=9.0-9035
ManageEngine ServiceDesk Plus=9.0-9036
ManageEngine ServiceDesk Plus=9.0-9037
ManageEngine ServiceDesk Plus=9.0-9038
ManageEngine ServiceDesk Plus=9.0-9039
ManageEngine ServiceDesk Plus=9.0-9040
ManageEngine ServiceDesk Plus=9.0-9041
ManageEngine ServiceDesk Plus=9.0-9042
ManageEngine ServiceDesk Plus=9.0-9043
ManageEngine ServiceDesk Plus=9.0-9044
ManageEngine ServiceDesk Plus=9.0-9045
ManageEngine ServiceDesk Plus=9.0-9046
ManageEngine ServiceDesk Plus=9.0-9047
ManageEngine ServiceDesk Plus=9.0-9048
ManageEngine ServiceDesk Plus=9.0-9049
ManageEngine ServiceDesk Plus=9.1
ManageEngine ServiceDesk Plus=9.1-9100
ManageEngine ServiceDesk Plus=9.1-9101
ManageEngine ServiceDesk Plus=9.1-9102
ManageEngine ServiceDesk Plus=9.1-9103
ManageEngine ServiceDesk Plus=9.1-9104
ManageEngine ServiceDesk Plus=9.1-9105
ManageEngine ServiceDesk Plus=9.1-9106
ManageEngine ServiceDesk Plus=9.1-9107
ManageEngine ServiceDesk Plus=9.1-9108
ManageEngine ServiceDesk Plus=9.1-9109
ManageEngine ServiceDesk Plus=9.1-9110
ManageEngine ServiceDesk Plus=9.1-9111
ManageEngine ServiceDesk Plus=9.1-9112
ManageEngine ServiceDesk Plus=9.1-9113
ManageEngine ServiceDesk Plus=9.1-9114
ManageEngine ServiceDesk Plus=9.1-9115
ManageEngine ServiceDesk Plus=9.1-9116
ManageEngine ServiceDesk Plus=9.1-9117
ManageEngine ServiceDesk Plus=9.1-9118
ManageEngine ServiceDesk Plus=9.1-9119
ManageEngine ServiceDesk Plus=9.1-9120
ManageEngine ServiceDesk Plus=9.1-9121
ManageEngine ServiceDesk Plus=9.2
ManageEngine ServiceDesk Plus=9.2-9200
ManageEngine ServiceDesk Plus=9.2-9201
ManageEngine ServiceDesk Plus=9.2-9202
ManageEngine ServiceDesk Plus=9.2-9203
ManageEngine ServiceDesk Plus=9.2-9204
ManageEngine ServiceDesk Plus=9.2-9205
ManageEngine ServiceDesk Plus=9.2-9206
ManageEngine ServiceDesk Plus=9.2-9207
ManageEngine ServiceDesk Plus=9.2-9208
ManageEngine ServiceDesk Plus=9.2-9209
ManageEngine ServiceDesk Plus=9.2-9210
ManageEngine ServiceDesk Plus=9.2-9211
ManageEngine ServiceDesk Plus=9.2-9212
ManageEngine ServiceDesk Plus=9.2-9213
ManageEngine ServiceDesk Plus=9.2-9214
ManageEngine ServiceDesk Plus=9.2-9215
ManageEngine ServiceDesk Plus=9.2-9216
ManageEngine ServiceDesk Plus=9.2-9217
ManageEngine ServiceDesk Plus=9.2-9218
ManageEngine ServiceDesk Plus=9.2-9219
ManageEngine ServiceDesk Plus=9.2-9220
ManageEngine ServiceDesk Plus=9.2-9221
ManageEngine ServiceDesk Plus=9.2-9222
ManageEngine ServiceDesk Plus=9.2-9223
ManageEngine ServiceDesk Plus=9.2-9224
ManageEngine ServiceDesk Plus=9.2-9225
ManageEngine ServiceDesk Plus=9.2-9226
ManageEngine ServiceDesk Plus=9.2-9227
ManageEngine ServiceDesk Plus=9.2-9228
ManageEngine ServiceDesk Plus=9.2-9229
ManageEngine ServiceDesk Plus=9.2-9230
ManageEngine ServiceDesk Plus=9.2-9231
ManageEngine ServiceDesk Plus=9.2-9232
ManageEngine ServiceDesk Plus=9.2-9233
ManageEngine ServiceDesk Plus=9.2-9234
ManageEngine ServiceDesk Plus=9.2-9235
ManageEngine ServiceDesk Plus=9.2-9236
ManageEngine ServiceDesk Plus=9.2-9237
ManageEngine ServiceDesk Plus=9.2-9238
ManageEngine ServiceDesk Plus=9.2-9239
ManageEngine ServiceDesk Plus=9.2-9240
ManageEngine ServiceDesk Plus=9.2-9241
ManageEngine ServiceDesk Plus=9.2-9242
ManageEngine ServiceDesk Plus=9.3
ManageEngine ServiceDesk Plus=9.3-9300
ManageEngine ServiceDesk Plus=9.3-9301
ManageEngine ServiceDesk Plus=9.3-9302
ManageEngine ServiceDesk Plus=9.3-9303
ManageEngine ServiceDesk Plus=9.3-9304
ManageEngine ServiceDesk Plus=9.3-9305
ManageEngine ServiceDesk Plus=9.3-9306
ManageEngine ServiceDesk Plus=9.3-9307
ManageEngine ServiceDesk Plus=9.3-9308
ManageEngine ServiceDesk Plus=9.3-9309
ManageEngine ServiceDesk Plus=9.3-9310
ManageEngine ServiceDesk Plus=9.3-9311
ManageEngine ServiceDesk Plus=9.3-9312
ManageEngine ServiceDesk Plus=9.3-9313
ManageEngine ServiceDesk Plus=9.3-9314
ManageEngine ServiceDesk Plus=9.3-9315
ManageEngine ServiceDesk Plus=9.3-9316
ManageEngine ServiceDesk Plus=9.3-9317
ManageEngine ServiceDesk Plus=9.3-9318
ManageEngine ServiceDesk Plus=9.3-9319
ManageEngine ServiceDesk Plus=9.3-9320
ManageEngine ServiceDesk Plus=9.3-9321
ManageEngine ServiceDesk Plus=9.3-9322
ManageEngine ServiceDesk Plus=9.3-9323
ManageEngine ServiceDesk Plus=9.3-9324
ManageEngine ServiceDesk Plus=9.3-9325
ManageEngine ServiceDesk Plus=9.3-9326
ManageEngine ServiceDesk Plus=9.3-9327
ManageEngine ServiceDesk Plus=9.3-9328
ManageEngine ServiceDesk Plus=9.3-9329
ManageEngine ServiceDesk Plus=9.3-9330
ManageEngine ServiceDesk Plus=9.3-9331
ManageEngine ServiceDesk Plus=9.3-9332
ManageEngine ServiceDesk Plus=9.3-9333
ManageEngine ServiceDesk Plus=9.3-9334
ManageEngine ServiceDesk Plus=9.3-9335
ManageEngine ServiceDesk Plus=9.3-9336
ManageEngine ServiceDesk Plus=9.4
ManageEngine ServiceDesk Plus=9.4-9400
ManageEngine ServiceDesk Plus=9.4-9401
ManageEngine ServiceDesk Plus=9.4-9402
ManageEngine ServiceDesk Plus=9.4-9403
ManageEngine ServiceDesk Plus=9.4-9404
ManageEngine ServiceDesk Plus=9.4-9405
ManageEngine ServiceDesk Plus=9.4-9406
ManageEngine ServiceDesk Plus=9.4-9407
ManageEngine ServiceDesk Plus=9.4-9408
ManageEngine ServiceDesk Plus=9.4-9409
ManageEngine ServiceDesk Plus=9.4-9410
ManageEngine ServiceDesk Plus=9.4-9411
ManageEngine ServiceDesk Plus=9.4-9412
ManageEngine ServiceDesk Plus=9.4-9413
ManageEngine ServiceDesk Plus=9.4-9414
ManageEngine ServiceDesk Plus=9.4-9415
ManageEngine ServiceDesk Plus=9.4-9416
ManageEngine ServiceDesk Plus=9.4-9417
ManageEngine ServiceDesk Plus=9.4-9418
ManageEngine ServiceDesk Plus=9.4-9419
ManageEngine ServiceDesk Plus=9.4-9420
ManageEngine ServiceDesk Plus=9.4-9421
ManageEngine ServiceDesk Plus=9.4-9422
ManageEngine ServiceDesk Plus=9.4-9423
ManageEngine ServiceDesk Plus=9.4-9424
ManageEngine ServiceDesk Plus=9.4-9425
ManageEngine ServiceDesk Plus=9.4-9426
ManageEngine ServiceDesk Plus=9.4-9427
ManageEngine ServiceDesk Plus=10.0
ManageEngine ServiceDesk Plus=10.0.0
ManageEngine ServiceDesk Plus=10.0.0-10000
ManageEngine ServiceDesk Plus=10.0.0-10001
ManageEngine ServiceDesk Plus=10.0.0-10002
ManageEngine ServiceDesk Plus=10.0.0-10003
ManageEngine ServiceDesk Plus=10.0.0-10004
ManageEngine ServiceDesk Plus=10.0.0-10005
ManageEngine ServiceDesk Plus=10.0.0-10006
ManageEngine ServiceDesk Plus=10.0.0-10007
ManageEngine ServiceDesk Plus=10.0.0-10008
ManageEngine ServiceDesk Plus=10.0.0-10009
ManageEngine ServiceDesk Plus=10.0.0-10010
ManageEngine ServiceDesk Plus=10.0.0-10011
ManageEngine ServiceDesk Plus=10.0.0-10012
ManageEngine ServiceDesk Plus=10.0.0-10013
ManageEngine ServiceDesk Plus=10.0.0-10014
ManageEngine ServiceDesk Plus=10.0.0-10015
ManageEngine ServiceDesk Plus=10.0.0-10016
ManageEngine ServiceDesk Plus=10.0.0-10017
ManageEngine ServiceDesk Plus=10.0.0-10018
ManageEngine ServiceDesk Plus=10.0.0-10019
ManageEngine ServiceDesk Plus=10.0.0-10020
ManageEngine ServiceDesk Plus=10.0.0-10021
ManageEngine ServiceDesk Plus=10.5
ManageEngine ServiceDesk Plus=10.5-10500
ManageEngine ServiceDesk Plus=10.5-10501
ManageEngine ServiceDesk Plus=10.5-10502
ManageEngine ServiceDesk Plus=10.5-10503
ManageEngine ServiceDesk Plus=10.5-10504
ManageEngine ServiceDesk Plus=10.5-10505
ManageEngine ServiceDesk Plus=10.5-10506
ManageEngine ServiceDesk Plus=10.5-10507
ManageEngine ServiceDesk Plus=10.5-10508
ManageEngine ServiceDesk Plus=10.5-10509
ManageEngine ServiceDesk Plus=10.5-10510
ManageEngine ServiceDesk Plus=10.5-10511
ManageEngine ServiceDesk Plus=10.5-10512
ManageEngine ServiceDesk Plus=10.5-10513
ManageEngine ServiceDesk Plus=10.5-10514
ManageEngine ServiceDesk Plus=11.0
ManageEngine ServiceDesk Plus=11.0-11000
ManageEngine ServiceDesk Plus=11.0-11001
ManageEngine ServiceDesk Plus=11.0-11002
ManageEngine ServiceDesk Plus=11.0-11003
ManageEngine ServiceDesk Plus=11.0-11004
ManageEngine ServiceDesk Plus=11.0-11005
ManageEngine ServiceDesk Plus=11.0-11006
ManageEngine ServiceDesk Plus=11.0-11007
ManageEngine ServiceDesk Plus=11.0-11008
ManageEngine ServiceDesk Plus=11.0-11009
ManageEngine ServiceDesk Plus=11.0-11010
ManageEngine ServiceDesk Plus=11.1
ManageEngine ServiceDesk Plus=11.1-11100
ManageEngine ServiceDesk Plus=11.1-11101
ManageEngine ServiceDesk Plus=11.1-11102
ManageEngine ServiceDesk Plus=11.1-11103
ManageEngine ServiceDesk Plus=11.1-11104
ManageEngine ServiceDesk Plus=11.1-11105
ManageEngine ServiceDesk Plus=11.1-11106
ManageEngine ServiceDesk Plus=11.1-11107
ManageEngine ServiceDesk Plus=11.1-11108
ManageEngine ServiceDesk Plus=11.1-11109
ManageEngine ServiceDesk Plus=11.1-11110
ManageEngine ServiceDesk Plus=11.1-11111
ManageEngine ServiceDesk Plus=11.1-11112
ManageEngine ServiceDesk Plus=11.1-11113
ManageEngine ServiceDesk Plus=11.1-11114
ManageEngine ServiceDesk Plus=11.1-11115
ManageEngine ServiceDesk Plus=11.1-11116
ManageEngine ServiceDesk Plus=11.1-11117
ManageEngine ServiceDesk Plus=11.1-build11118
ManageEngine ServiceDesk Plus=11.1-build11119

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2021-20080?

    CVE-2021-20080 is classified as a high severity vulnerability due to its potential for persistent cross-site scripting (XSS) attacks.

  • How do I fix CVE-2021-20080?

    To fix CVE-2021-20080, users should update their ManageEngine ServiceDesk Plus and AssetExplorer to versions 11200 and 6800 or later, respectively.

  • Who is affected by CVE-2021-20080?

    CVE-2021-20080 affects users of ManageEngine ServiceDesk Plus versions prior to 11200 and AssetExplorer versions before 6800.

  • What type of attack can be executed using CVE-2021-20080?

    CVE-2021-20080 allows remote, unauthenticated attackers to conduct persistent cross-site scripting (XSS) attacks.

  • What does insufficient output sanitization mean in the context of CVE-2021-20080?

    Insufficient output sanitization in CVE-2021-20080 means that the application fails to properly clean or escape user input, leading to the potential execution of malicious scripts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203