First published: Thu Jan 27 2022(Updated: )
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | =11.3-11306 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46065 is a Cross-site scripting (XSS) vulnerability in the Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306.
CVE-2021-46065 has a severity value of 4.8, which is classified as medium severity.
CVE-2021-46065 allows attackers to inject arbitrary JavaScript code through the Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306.
To fix CVE-2021-46065, it is recommended to update Zoho ManageEngine ServiceDesk Plus to a version that has addressed the vulnerability.
You can find more information about CVE-2021-46065 at the following references: [link1](https://github.com/corrupted-brain/Findings/blob/main/ManageEngine%20XSS.md) and [link2](https://www.manageengine.com/products/service-desk/on-premises/readme.html).