CVE-2021-27214: XSS
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27214?
The severity of CVE-2021-27214 is medium with a CVSS score of 6.1.
How does CVE-2021-27214 affect Zoho ManageEngine ADSelfService Plus?
CVE-2021-27214 affects Zoho ManageEngine ADSelfService Plus versions 6.0 through 6013.
What is the vulnerability description of CVE-2021-27214?
CVE-2021-27214 is a Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus that allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP.
How can an attacker exploit CVE-2021-27214?
An attacker can exploit CVE-2021-27214 by sending malicious requests to the ProductConfig servlet and potentially perform actions on behalf of the application or access sensitive information.
Are there any references available for CVE-2021-27214?
Yes, you can find references for CVE-2021-27214 at the following links: [Reference 1](https://www.horizonsecurity.it/lang_EN/advisories/?a=20&title=ManageEngine+ADSelfService+Plus+privilege+escalation++CVE202127214), [Reference 2](https://www.manageengine.com/products/self-service-password/release-notes.html).