blog.stmcyber.com
https://blog.stmcyber.com/vulns/cve-2021-37416 CVE-2021-37416
MEDIUMNuclei
Zoho ManageEngine ADSelfService Plus <=6103 - Cross-Site Scripting
Record summary
CVE-2021-37416 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMZoho ManageEngine ADSelfService Plus <=6103 - Cross-Site ScriptingCVSS 6.1
Zoho ManageEngine ADSelfService Plus 6103 and prior contains a reflected cross-site scripting vulnerability on the loadframe page.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected user's browser.
Remediation
Upgrade to a patched version of Zoho ManageEngine ADSelfService Plus (version >6103) to mitigate this vulnerability.
WeaknessesCWE-79
Authorsedoardottt
Template tagscve2021cvezohoxsszohocorpvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*
Shodan: http.title:"ManageEngine"
Shodan: http.title:"adselfservice plus"
Shodan: http.title:"manageengine"
FOFA: title="manageengine"
FOFA: title="adselfservice plus"
Google: intitle:"adselfservice plus"
Google: intitle:"manageengine"
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37416 https://blog.stmcyber.com/vulns/cve-2021-37416/ https://nvd.nist.gov/vuln/detail/CVE-2021-37416 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-37416