← Vulnerability feed

Vulnerability record · CVE-2021-33256 · published 9 August 2021

CVE-2021-33256: ManageEngine ADSelfService Plus login panel CSV injection

Zohocorp · Manageengine Adselfservice Plus

The login panel of ManageEngine ADSelfService Plus 6.1 (build 6101) fails to sanitize the j_username parameter, allowing CSV injection. When a privileged user exports the "User Attempts Audit Report" as a CSV file, injected formulas can execute, potentially leading to a reverse shell. The vendor disputes this, stating it is not a valid vulnerability in their product.

8.8 CVSS 3.1 High EPSS 79% · top 0.4% CWE-1236 · CSV injection
8.8CVSS 3.1 base score, v2 9.3
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.8 and a very high EPSS score indicate significant risk, though exploitation requires a privileged user to export and open the CSV, and the vendor disputes the issue.

What it is

The login panel of ManageEngine ADSelfService Plus 6.1 (build 6101) fails to sanitize the j_username parameter, allowing CSV injection. When a privileged user exports the "User Attempts Audit Report" as a CSV file, injected formulas can execute, potentially leading to a reverse shell. The vendor disputes this, stating it is not a valid vulnerability in their product.

Impact

An unauthenticated attacker can inject malicious content that executes when a privileged administrator opens the exported CSV report, potentially gaining code execution in the context of that user.

Attack surface

Reachable over the network through the login panel's j_username parameter with no authentication required, but exploitation depends on a privileged user exporting the audit report as CSV, so user interaction is required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.79, 99.6th percentile) and the only references are tagged Exploit and Third Party Advisory, indicating public exploit detail exists.

What to do

  • Apply the latest ADSelfService Plus build from the vendor, since the affected 6.1 build 6101 is old; verify whether the vendor has addressed the disputed issue in a later release.
  • Restrict access to the login panel and audit report export functionality to trusted networks or administrators only.
  • Sanitize or escape user-supplied input such as j_username before it is written into exported CSV files.
  • Train privileged users not to open exported CSV reports in spreadsheet software that evaluates formulas, or open them in a safe viewer.
  • Monitor vendor advisories because the vendor disputes the finding and may not issue a fix.

Detection

  • Review ADSelfService Plus logs for suspicious characters (for example =, +, -, @) in the j_username parameter of login attempts.
  • Monitor for unexpected outbound connections from hosts where administrators open exported CSV reports.
  • Audit creation and access of "User Attempts Audit Report" CSV exports for unusual timing or volume.
  • Inspect exported CSV files for formula-like content before they are opened.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-40539Zoho ManageEngine ADSelfService Plus REST API auth bypass to RCEZoho ManageEngine ADSelfService Plus version 6113 and prior contains an authentication bypass in its REST API that leads to remote code execution. Be…KEVEPSS 99%analysed6.8CVE-2022-28810Zoho ManageEngine ADSelfService Plus OS command injection via custom scriptZoho ManageEngine ADSelfService Plus before build 6122 lets a remote authenticated administrator run arbitrary OS commands as SYSTEM through the poli…KEVEPSS 71%analysed10.0CVE-2019-3905Zohocorp manageengine adselfservice plus server-side request forgery (ssrf) vulnerabilityZoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.EPSS 3.3%9.8CVE-2023-35854Zohocorp manageengine adselfservice plus missing authentication for critical function vulnerabilityZoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for…EPSS 6.0%9.8CVE-2021-37422Zohocorp manageengine adselfservice plus sql injection vulnerabilityZoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.EPSS 3.4%9.8CVE-2021-37423Zohocorp manageengine adselfservice plus vulnerabilityZoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.EPSS 2.8%9.8CVE-2021-37417Zohocorp manageengine adselfservice plus improper authentication vulnerabilityZoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.EPSS 4.8%

Source: NIST National Vulnerability Database (record CVE-2021-33256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.