Vulnerability record · CVE-2021-33256 · published 9 August 2021
CVE-2021-33256: ManageEngine ADSelfService Plus login panel CSV injection
Zohocorp · Manageengine Adselfservice Plus
The login panel of ManageEngine ADSelfService Plus 6.1 (build 6101) fails to sanitize the j_username parameter, allowing CSV injection. When a privileged user exports the "User Attempts Audit Report" as a CSV file, injected formulas can execute, potentially leading to a reverse shell. The vendor disputes this, stating it is not a valid vulnerability in their product.
Description
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 and a very high EPSS score indicate significant risk, though exploitation requires a privileged user to export and open the CSV, and the vendor disputes the issue.
What it is
The login panel of ManageEngine ADSelfService Plus 6.1 (build 6101) fails to sanitize the j_username parameter, allowing CSV injection. When a privileged user exports the "User Attempts Audit Report" as a CSV file, injected formulas can execute, potentially leading to a reverse shell. The vendor disputes this, stating it is not a valid vulnerability in their product.
Impact
An unauthenticated attacker can inject malicious content that executes when a privileged administrator opens the exported CSV report, potentially gaining code execution in the context of that user.
Attack surface
Reachable over the network through the login panel's j_username parameter with no authentication required, but exploitation depends on a privileged user exporting the audit report as CSV, so user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.79, 99.6th percentile) and the only references are tagged Exploit and Third Party Advisory, indicating public exploit detail exists.
What to do
- Apply the latest ADSelfService Plus build from the vendor, since the affected 6.1 build 6101 is old; verify whether the vendor has addressed the disputed issue in a later release.
- Restrict access to the login panel and audit report export functionality to trusted networks or administrators only.
- Sanitize or escape user-supplied input such as j_username before it is written into exported CSV files.
- Train privileged users not to open exported CSV reports in spreadsheet software that evaluates formulas, or open them in a safe viewer.
- Monitor vendor advisories because the vendor disputes the finding and may not issue a fix.
Detection
- Review ADSelfService Plus logs for suspicious characters (for example =, +, -, @) in the j_username parameter of login attempts.
- Monitor for unexpected outbound connections from hosts where administrators open exported CSV reports.
- Audit creation and access of "User Attempts Audit Report" CSV exports for unusual timing or volume.
- Inspect exported CSV files for formula-like content before they are opened.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.unsafe-inline.com/0day/manageengine-adselfservice-plus-6.1-csv-injection | ExploitThird Party Advisory |
| https://docs.unsafe-inline.com/0day/manageengine-adselfservice-plus-6.1-csv-injection | ExploitThird Party Advisory |
Track CVE-2021-33256 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.