Vulnerability record · CVE-2021-31813 · published 1 July 2021
CVE-2021-31813: Zoho ManageEngine Applications Manager stored XSS via AD user import
Zohocorp · Manageengine Applications Manager
Zoho ManageEngine Applications Manager before build 15130 stores attacker-controlled user details imported from Active Directory without proper output encoding, creating a stored cross-site scripting condition. Because the payload persists in the application and is rendered to other users, it can affect administrators and operators who view the imported user data.
Description
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) and it requires authentication plus user interaction, though the high EPSS and public exploit references raise concern.
What it is
Zoho ManageEngine Applications Manager before build 15130 stores attacker-controlled user details imported from Active Directory without proper output encoding, creating a stored cross-site scripting condition. Because the payload persists in the application and is rendered to other users, it can affect administrators and operators who view the imported user data.
Impact
An attacker can execute script in the browser context of a victim user, potentially stealing session tokens or performing actions as that user. The CVSS scope change indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network through the AD user import functionality; the vector requires low privileges (PR:L) and user interaction (UI:R), meaning an authenticated actor must supply the crafted user detail and a victim must view the affected page.
Exploitation
No CISA KEV listing, but EPSS is very high at 0.783 (99.6th percentile) and third-party references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Applications Manager to build 15130 or later per the vendor advisory.
- Restrict and audit who can configure or trigger AD user imports.
- Sanitize and validate imported AD attributes before storage and encode on output.
- Apply content security policy and session cookie protections to limit XSS impact.
Detection
- Search application and web logs for AD import operations containing script tags or unusual characters in user names.
- Monitor for anomalous authenticated sessions or requests originating after user import events.
- Review stored user records for HTML or JavaScript payloads in name and detail fields.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://raxis.com/blog/cve-2021-31813 | ExploitThird Party Advisory |
| https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2021-31813.html | Vendor Advisory |
| https://raxis.com/blog/cve-2021-31813 | ExploitThird Party Advisory |
| https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2021-31813.html | Vendor Advisory |
Track CVE-2021-31813 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-31813), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.