Cross-Site Scripting Vulnerability in ManageEngine ServiceDesk Plus and AssetExplorer
CVE-2021-20080

6.1MEDIUM

What is CVE-2021-20080?

A vulnerability exists in ManageEngine ServiceDesk Plus versions prior to 11200 and ManageEngine AssetExplorer versions prior to 6800, which exposes the platforms to persistent cross-site scripting (XSS) attacks. This is due to insufficient output sanitization that allows an unauthenticated remote attacker to upload a specially crafted XML asset file. If exploited, this can enable attackers to execute arbitrary scripts in the context of users accessing affected instances, potentially leading to data theft and unauthorized actions.

Affected Version(s)

ManageEngine AssetExplorer Before 6800

ManageEngine ServiceDesk Plus Before 11200

References

EPSS Score

35% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.