CVE-2021-27214
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.
Una vulnerabilidad de tipo Server-side request forgery (SSRF) en el servlet ProductConfig en Zoho ManageEngine ADSelfService Plus versiones hasta 6013, permite a un atacante remoto no autenticado realizar peticiones HTTP ciegas o realizar un ataque de tipo Cross-site scripting (XSS) contra la interfaz administrativa por medio de una peticiĆ³n HTTP, una vulnerabilidad diferente a CVE-2019-3905
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-02-14 CVE Reserved
- 2021-02-19 CVE Published
- 2024-02-23 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.horizonsecurity.it/lang_EN/advisories/?a=20&title=ManageEngine+ADSelfService+Plus+privilege+escalation++CVE202127214 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.manageengine.com/products/self-service-password/release-notes.html | 2022-07-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | - |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6000 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6001 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6002 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6003 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6004 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6005 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6006 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6007 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6008 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6009 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6012 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.0 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.0" | 6013 |
Affected
|