
Cloud Vulnerability DB
A community-led vulnerabilities database
Zoho ManageEngine Key Manager Plus before version 6001 contained a stored Cross-Site Scripting (XSS) vulnerability (CVE-2021-28382). The vulnerability was discovered in March 2021 and affected the user-management page when importing malicious user details from Active Directory (Raxis Blog, NVD).
The vulnerability exists in any of the user's details fields when they are imported from Active Directory. The XSS can be triggered by inserting HTML content, specifically script tags, into the first name, last name, or email field of an Active Directory user. When visiting the /apiclient/index.jsp#/Settings/UserManagement page, the user's details are loaded with unescaped content, allowing for malicious JavaScript to be executed. The vulnerability has been assigned a CVSS v3.1 base score of 5.4 (Medium) with vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N (NVD, Raxis Blog).
When exploited, this vulnerability could allow attackers to execute arbitrary JavaScript code in the context of other users' browsers who visit the affected user management page. This could potentially lead to the theft of sensitive information, including session cookies and other user data (Raxis Blog).
The vulnerability was demonstrated to be exploitable by inserting malicious JavaScript code into Active Directory user fields. A proof of concept showed that an attacker could execute JavaScript commands such as accessing document cookies when the affected page was loaded (Raxis Blog).
The vulnerability was patched in ManageEngine Key Manager Plus version 6001. Organizations using affected versions should upgrade to version 6001 or later immediately to mitigate this security risk (ManageEngine Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."