CVE-2021-20080 is a vulnerability in Zoho Corp Manageengine Servicedesk Plus
Published on April 9, 2021
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.
Products Associated with CVE-2021-20080
Want to know whenever a new CVE is published for Zoho Corp Manageengine Servicedesk Plus? stack.watch will email you.
Exploit Probability
EPSS
18.64%
Percentile
95.20%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.