CVE-2021-20080 is a vulnerability in Zoho Corp Manageengine Servicedesk Plus
Published on April 9, 2021
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.
Products Associated with CVE-2021-20080
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2021-20080 are published in Zoho Corp Manageengine Servicedesk Plus:
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.