← Vulnerability feed

Vulnerability record · CVE-2021-20080 · published 9 April 2021

CVE-2021-20080: ManageEngine ServiceDesk Plus and AssetExplorer persistent XSS via crafted XML asset upload

Zohocorp · Manageengine Servicedesk Plus

ManageEngine ServiceDesk Plus before 11200 and AssetExplorer before 6800 fail to sanitize output when handling uploaded XML asset files, allowing stored cross-site scripting. Because the payload persists in the application, it can execute in the browser of any user who later views the affected asset content.

6.1 CVSS 3.1 Medium EPSS 93% · top 0.2% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityHigh EPSS and public exploit references raise real exploitation likelihood, though the CVSS score is only medium and KEV does not list it.

What it is

ManageEngine ServiceDesk Plus before 11200 and AssetExplorer before 6800 fail to sanitize output when handling uploaded XML asset files, allowing stored cross-site scripting. Because the payload persists in the application, it can execute in the browser of any user who later views the affected asset content.

Impact

An attacker can run script in a victim's authenticated session, enabling session theft, credential capture or actions performed as the victim within the application.

Attack surface

Reachable over the network by an unauthenticated attacker who uploads a crafted XML asset file; successful execution requires a victim to view the injected content, so user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.93108, 99.8th percentile) and both references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade ServiceDesk Plus to version 11200 or later and AssetExplorer to version 6800 or later.
  • Restrict or disable unauthenticated asset/XML upload paths until patched.
  • Apply output encoding and input validation on asset file processing and rendering.
  • Deploy a WAF rule to block script content in uploaded XML asset files.

Detection

  • Monitor asset upload endpoints for XML files containing script tags or event handler attributes.
  • Search application logs and stored asset content for injected script payloads.
  • Alert on anomalous authenticated sessions or actions following asset views by privileged users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20080 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-44077Zoho ManageEngine ServiceDesk Plus unauthenticated RCEZoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling…KEVEPSS 93%analysed9.8CVE-2021-37415Zoho ManageEngine ServiceDesk Plus authentication bypass via REST APIZoho ManageEngine ServiceDesk Plus before build 11302 contains an authentication bypass (CWE-306) that lets a small number of REST-API URLs be reache…KEVEPSS 100%analysed6.5CVE-2019-8394Zoho ManageEngine ServiceDesk Plus unrestricted file upload via login page customizationZoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization fe…KEVEPSS 63%analysed9.8CVE-2021-44526Zohocorp manageengine servicedesk plus vulnerabilityZoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.EPSS 3.2%9.8CVE-2019-8395Zohocorp manageengine servicedesk plus path traversal vulnerabilityAn Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment…EPSS 7.1%8.8CVE-2020-35682Zohocorp manageengine servicedesk plus incorrect authorization vulnerabilityZoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).EPSS 7.2%8.8CVE-2017-9362Zohocorp manageengine servicedesk plus xml external entity (xxe) vulnerabilityManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2021-20080), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.