CVE-2021-36771: XSS
Published Jul 17, 2021
·Updated
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
Affected Software
5 affected components
ZohoCorp ManageEngine ADManager Plus<7.1
ZohoCorp ManageEngine ADManager Plus=7.1
ZohoCorp ManageEngine ADManager Plus=7.1-7100
ZohoCorp ManageEngine ADManager Plus=7.1-7101
ZohoCorp ManageEngine ADManager Plus=7.1-7102
Event History
Jul 17, 2021
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
Description
Frequently Asked Questions
1
What is CVE-2021-36771?
CVE-2021-36771 is a vulnerability that allows for reflected XSS in Zoho ManageEngine ADManager Plus before version 7110.
2
What is the severity of CVE-2021-36771?
The severity of CVE-2021-36771 is medium, with a CVSS score of 6.1.
3
What software is affected by CVE-2021-36771?
Zoho ManageEngine ADManager Plus versions up to and including 7.1-7102 are affected by CVE-2021-36771.
4
How can I fix CVE-2021-36771?
To fix CVE-2021-36771, users should upgrade to version 7.1-7110 of Zoho ManageEngine ADManager Plus.
5
Are there any additional references for CVE-2021-36771?
Yes, you may refer to the release notes of Zoho ManageEngine ADManager Plus for more information: https://www.manageengine.com/products/ad-manager/release-notes.html#7110