First published: Thu May 20 2021(Updated: )
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Adselfservice Plus | <6.1 | |
Zohocorp Manageengine Adselfservice Plus | =6.1 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6100 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6103 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27956 is a vulnerability that allows stored XSS (cross-site scripting) in Zoho ManageEngine ADSelfService Plus before version 6104.
CVE-2021-27956 has a severity rating of 6.1 (medium).
CVE-2021-27956 affects Zoho ManageEngine ADSelfService Plus versions before 6104 by allowing stored XSS through the e-mail address field on the /webclient/index.html#/directory-search user search page.
Yes, the fix for CVE-2021-27956 is included in version 6104 of Zoho ManageEngine ADSelfService Plus.
More information about CVE-2021-27956 can be found in the following references: [Reference 1](https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6104-released-with-an-important-security-fixes), [Reference 2](https://raxis.com/blog/cve-2021-27956-manage-engine-xss), [Reference 3](https://www.manageengine.com).