CVE-2021-36772: XSS
Published Jul 17, 2021
·Updated
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
Affected Software
5 affected components
ZohoCorp ManageEngine ADManager Plus<7.1
ZohoCorp ManageEngine ADManager Plus=7.1
ZohoCorp ManageEngine ADManager Plus=7.1-7100
ZohoCorp ManageEngine ADManager Plus=7.1-7101
ZohoCorp ManageEngine ADManager Plus=7.1-7102
Event History
Jul 17, 2021
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-36772?
The severity of CVE-2021-36772 is medium with a CVSS score of 6.1.
2
What is the affected software?
The affected software is Zoho ManageEngine ADManager Plus versions up to 7.1-7102.
3
What is the vulnerability in Zoho ManageEngine ADManager Plus?
The vulnerability in Zoho ManageEngine ADManager Plus is a stored cross-site scripting (XSS) vulnerability.
4
How can I fix the vulnerability?
To fix the vulnerability, update Zoho ManageEngine ADManager Plus to version 7.1-7110 or later.
5
Where can I find more information about the vulnerability?
More information about the vulnerability can be found at the following URL: https://www.manageengine.com/products/ad-manager/release-notes.html#7110