CVE-2021-31813: XSS
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31813?
CVE-2021-31813 is a vulnerability in Zoho ManageEngine Applications Manager that allows for Stored XSS attacks when importing malicious user details.
What software versions are affected by CVE-2021-31813?
Zoho ManageEngine Applications Manager versions up to and including 15.1.15130 are affected.
What is the severity of CVE-2021-31813?
CVE-2021-31813 has a severity rating of 5.4, which is considered medium.
How can I fix CVE-2021-31813 vulnerability?
To fix the CVE-2021-31813 vulnerability, update Zoho ManageEngine Applications Manager to version 15.1.15130 or higher.
Where can I find more information about CVE-2021-31813?
You can find more information about CVE-2021-31813 at the following references: [link1](https://raxis.com/blog/cve-2021-31813), [link2](https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2021-31813.html).