Stored XSS Vulnerability in Zoho ManageEngine Key Manager Plus Allows Injection of Malicious User Details from AD

Stored XSS Vulnerability in Zoho ManageEngine Key Manager Plus Allows Injection of Malicious User Details from AD

CVE-2021-28382 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.

Learn more about our User Device Pen Test.