Record summary

CVE-2021-37416 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMZoho ManageEngine ADSelfService Plus <=6103 - Cross-Site ScriptingCVSS 6.1

Zoho ManageEngine ADSelfService Plus 6103 and prior contains a reflected cross-site scripting vulnerability on the loadframe page.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected user's browser.

Remediation

Upgrade to a patched version of Zoho ManageEngine ADSelfService Plus (version >6103) to mitigate this vulnerability.

WeaknessesCWE-79
Authorsedoardottt
Template tagscve2021cvezohoxsszohocorpvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*
Shodan: http.title:"ManageEngine"
Shodan: http.title:"adselfservice plus"
Shodan: http.title:"manageengine"
FOFA: title="manageengine"
FOFA: title="adselfservice plus"
Google: intitle:"adselfservice plus"
Google: intitle:"manageengine"

Source: ProjectDiscovery

References

2