CVE-2021-28382
Zoho ManageEngine Key Manager Plus vulnerability analysis and mitigation

Overview

Zoho ManageEngine Key Manager Plus before version 6001 contained a stored Cross-Site Scripting (XSS) vulnerability (CVE-2021-28382). The vulnerability was discovered in March 2021 and affected the user-management page when importing malicious user details from Active Directory (Raxis Blog, NVD).

Technical details

The vulnerability exists in any of the user's details fields when they are imported from Active Directory. The XSS can be triggered by inserting HTML content, specifically script tags, into the first name, last name, or email field of an Active Directory user. When visiting the /apiclient/index.jsp#/Settings/UserManagement page, the user's details are loaded with unescaped content, allowing for malicious JavaScript to be executed. The vulnerability has been assigned a CVSS v3.1 base score of 5.4 (Medium) with vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N (NVD, Raxis Blog).

Impact

When exploited, this vulnerability could allow attackers to execute arbitrary JavaScript code in the context of other users' browsers who visit the affected user management page. This could potentially lead to the theft of sensitive information, including session cookies and other user data (Raxis Blog).

Exploitability

The vulnerability was demonstrated to be exploitable by inserting malicious JavaScript code into Active Directory user fields. A proof of concept showed that an attacker could execute JavaScript commands such as accessing document cookies when the affected page was loaded (Raxis Blog).

Mitigation and workarounds

The vulnerability was patched in ManageEngine Key Manager Plus version 6001. Organizations using affected versions should upgrade to version 6001 or later immediately to mitigate this security risk (ManageEngine Release Notes).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine Key Manager Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-47966CRITICAL9.8
  • Zoho ManageEngine ServiceDesk Plus logoZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:application_control_plus
YesYesJan 18, 2023
CVE-2019-12133HIGH7.8
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_key_manager_plus
NoYesJun 18, 2019
CVE-2022-24447MEDIUM6.5
  • Zoho ManageEngine Key Manager Plus logoZoho ManageEngine Key Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_key_manager_plus
NoYesMar 02, 2022
CVE-2021-28382MEDIUM5.4
  • Zoho ManageEngine Key Manager Plus logoZoho ManageEngine Key Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_key_manager_plus
NoYesJun 07, 2021
CVE-2022-24446MEDIUM4.3
  • Zoho ManageEngine Key Manager Plus logoZoho ManageEngine Key Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_key_manager_plus
NoYesMar 01, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management