CVE-2021-27956
20.05.2021, 18:15
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_adselfservice_plus | 𝑥 < 6.1 |
| zohocorp | manageengine_adselfservice_plus | 6.1 |
| zohocorp | manageengine_adselfservice_plus | 6.1:6100 |
| zohocorp | manageengine_adselfservice_plus | 6.1:6103 |
𝑥
= Vulnerable software versions
References