← Vulnerability feed

Vulnerability record · CVE-2021-31813 · published 1 July 2021

CVE-2021-31813: Zoho ManageEngine Applications Manager stored XSS via AD user import

Zohocorp · Manageengine Applications Manager

Zoho ManageEngine Applications Manager before build 15130 stores attacker-controlled user details imported from Active Directory without proper output encoding, creating a stored cross-site scripting condition. Because the payload persists in the application and is rendered to other users, it can affect administrators and operators who view the imported user data.

5.4 CVSS 3.1 Medium EPSS 78% · top 0.4% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityCVSS rates it medium (5.4) and it requires authentication plus user interaction, though the high EPSS and public exploit references raise concern.

What it is

Zoho ManageEngine Applications Manager before build 15130 stores attacker-controlled user details imported from Active Directory without proper output encoding, creating a stored cross-site scripting condition. Because the payload persists in the application and is rendered to other users, it can affect administrators and operators who view the imported user data.

Impact

An attacker can execute script in the browser context of a victim user, potentially stealing session tokens or performing actions as that user. The CVSS scope change indicates impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network through the AD user import functionality; the vector requires low privileges (PR:L) and user interaction (UI:R), meaning an authenticated actor must supply the crafted user detail and a victim must view the affected page.

Exploitation

No CISA KEV listing, but EPSS is very high at 0.783 (99.6th percentile) and third-party references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Applications Manager to build 15130 or later per the vendor advisory.
  • Restrict and audit who can configure or trigger AD user imports.
  • Sanitize and validate imported AD attributes before storage and encode on output.
  • Apply content security policy and session cookie protections to limit XSS impact.

Detection

  • Search application and web logs for AD import operations containing script tags or unusual characters in user names.
  • Monitor for anomalous authenticated sessions or requests originating after user import events.
  • Review stored user records for HTML or JavaScript payloads in name and detail fields.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-31813 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-24743Zohocorp manageengine applications manager vulnerabilityAn issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resou…EPSS 2.8%9.8CVE-2020-27995Zohocorp manageengine applications manager sql injection vulnerabilitySQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do templa…EPSS 8.8%9.8CVE-2020-15533Zohocorp manageengine applications manager sql injection vulnerabilityIn Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to un…EPSS 4.2%9.8CVE-2020-15394Zohocorp manageengine applications manager sql injection vulnerabilityThe REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to R…EPSS 7.9%9.8CVE-2019-19649Zohocorp manageengine applications manager sql injection vulnerabilityZoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the S…EPSS 9.5%9.8CVE-2019-11469Zohocorp manageengine applications manager sql injection vulnerabilityZoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user …EPSS 17%9.8CVE-2019-11448Zohocorp manageengine applications manager sql injection vulnerabilityAn issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the …EPSS 12%9.8CVE-2018-15168Zohocorp manageengine applications manager sql injection vulnerabilityA SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplayna…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2021-31813), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.