Cross-Site Scripting Vulnerability in ManageEngine ServiceDesk Plus and AssetExplorer
CVE-2021-20080
6.1MEDIUM
What is CVE-2021-20080?
A vulnerability exists in ManageEngine ServiceDesk Plus versions prior to 11200 and ManageEngine AssetExplorer versions prior to 6800, which exposes the platforms to persistent cross-site scripting (XSS) attacks. This is due to insufficient output sanitization that allows an unauthenticated remote attacker to upload a specially crafted XML asset file. If exploited, this can enable attackers to execute arbitrary scripts in the context of users accessing affected instances, potentially leading to data theft and unauthorized actions.
Affected Version(s)
ManageEngine AssetExplorer Before 6800
ManageEngine ServiceDesk Plus Before 11200
References
EPSS Score
35% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved