Stored Cross-Site Scripting Vulnerability in Zoho ManageEngine Key Manager Plus
CVE-2021-28382

5.4MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
7 June 2021

What is CVE-2021-28382?

Zoho ManageEngine Key Manager Plus prior to version 6001 is susceptible to a stored cross-site scripting vulnerability. This issue arises during user management when importing user details from Active Directory. Attackers can exploit this vulnerability by using malicious payloads in the user details, potentially leading to unauthorized access or session hijacking for affected users.

References

EPSS Score

19% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.