CVE-2021-27956: XSS
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27956?
CVE-2021-27956 is a vulnerability that allows stored XSS (cross-site scripting) in Zoho ManageEngine ADSelfService Plus before version 6104.
How severe is CVE-2021-27956?
CVE-2021-27956 has a severity rating of 6.1 (medium).
How does CVE-2021-27956 affect Zoho ManageEngine ADSelfService Plus?
CVE-2021-27956 affects Zoho ManageEngine ADSelfService Plus versions before 6104 by allowing stored XSS through the e-mail address field on the /webclient/index.html#/directory-search user search page.
Is there a fix for CVE-2021-27956?
Yes, the fix for CVE-2021-27956 is included in version 6104 of Zoho ManageEngine ADSelfService Plus.
Where can I find more information about CVE-2021-27956?
More information about CVE-2021-27956 can be found in the following references: [Reference 1](https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6104-released-with-an-important-security-fixes), [Reference 2](https://raxis.com/blog/cve-2021-27956-manage-engine-xss), [Reference 3](https://www.manageengine.com).