CVE-2021-27214

MEDIUM

ManageEngine ADSelfService Plus <= 6013 - Unauthenticated Server-Side Request Forgery via ProductConfig Servlet

Title source: llm
STIX 2.1

Description

A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.

Scores

CVSS v3 6.1
EPSS 0.0730
EPSS Percentile 91.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-918 CWE-79
Status published
Products (1)
zohocorp/manageengine_adselfservice_plus 6.0 (13 CPE variants)
Published Feb 19, 2021
Tracked Since Feb 18, 2026