Vulnerability record · CVE-2021-20080 · published 9 April 2021
CVE-2021-20080: ManageEngine ServiceDesk Plus and AssetExplorer persistent XSS via crafted XML asset upload
Zohocorp · Manageengine Servicedesk Plus
ManageEngine ServiceDesk Plus before 11200 and AssetExplorer before 6800 fail to sanitize output when handling uploaded XML asset files, allowing stored cross-site scripting. Because the payload persists in the application, it can execute in the browser of any user who later views the affected asset content.
Description
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityHigh EPSS and public exploit references raise real exploitation likelihood, though the CVSS score is only medium and KEV does not list it.
What it is
ManageEngine ServiceDesk Plus before 11200 and AssetExplorer before 6800 fail to sanitize output when handling uploaded XML asset files, allowing stored cross-site scripting. Because the payload persists in the application, it can execute in the browser of any user who later views the affected asset content.
Impact
An attacker can run script in a victim's authenticated session, enabling session theft, credential capture or actions performed as the victim within the application.
Attack surface
Reachable over the network by an unauthenticated attacker who uploads a crafted XML asset file; successful execution requires a victim to view the injected content, so user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.93108, 99.8th percentile) and both references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade ServiceDesk Plus to version 11200 or later and AssetExplorer to version 6800 or later.
- Restrict or disable unauthenticated asset/XML upload paths until patched.
- Apply output encoding and input validation on asset file processing and rendering.
- Deploy a WAF rule to block script content in uploaded XML asset files.
Detection
- Monitor asset upload endpoints for XML files containing script tags or event handler attributes.
- Search application logs and stored asset content for injected script payloads.
- Alert on anomalous authenticated sessions or actions following asset views by privileged users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tenable.com/security/research/tra-2021-11 | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2021-11 | ExploitThird Party Advisory |
Track CVE-2021-20080 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20080), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.