mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-13 10:04:45 +02:00
994 B
994 B
CVE-2021-20080
Description
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.
POC
Reference
- https://www.tenable.com/security/research/tra-2021-11
- https://www.tenable.com/security/research/tra-2021-11