Vulnerability record · CVE-2021-46065 · published 27 January 2022
CVE-2021-46065: Zoho ManageEngine ServiceDesk Plus secondary email field XSS
Zohocorp · Manageengine Servicedesk Plus
A stored cross-site scripting flaw exists in the Secondary Email field of Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306, allowing injection of arbitrary JavaScript. Because the field is rendered to other users, injected script can run in their browsers within the application context.
Description
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (4.8) and it requires high privileges plus user interaction, though public exploit code and very high EPSS raise concern.
What it is
A stored cross-site scripting flaw exists in the Secondary Email field of Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306, allowing injection of arbitrary JavaScript. Because the field is rendered to other users, injected script can run in their browsers within the application context.
Impact
An attacker can execute arbitrary JavaScript in the browser of a user viewing the affected field, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the application's web interface. The vector requires high privileges (PR:H) and user interaction (UI:R), so an authenticated high-privilege user must enter the payload and a victim must view the affected field.
Exploitation
No CISA KEV listing, but EPSS is very high (0.91737, 99.81st percentile) and public exploit references are tagged Exploit, indicating known public proof-of-concept code. No ransomware association is documented.
What to do
- Apply the vendor fix referenced in the ManageEngine ServiceDesk Plus release notes and upgrade beyond Build 11306.
- Restrict access to the ServiceDesk Plus web interface to trusted networks and limit high-privilege accounts.
- Validate and sanitize or encode the Secondary Email field on input and output.
- Deploy a web application firewall or content security policy to reduce script execution impact.
Detection
- Search application and web logs for script tags or JavaScript payloads submitted to the Secondary Email field.
- Monitor for anomalous requests to ServiceDesk Plus endpoints containing encoded script content.
- Review accounts with high privileges for unexpected changes to email or profile fields.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/corrupted-brain/Findings/blob/main/ManageEngine%20XSS.md | ExploitThird Party Advisory |
| https://www.manageengine.com/products/service-desk/on-premises/readme.html | Release NotesThird Party Advisory |
| https://github.com/corrupted-brain/Findings/blob/main/ManageEngine%20XSS.md | ExploitThird Party Advisory |
| https://www.manageengine.com/products/service-desk/on-premises/readme.html | Release NotesThird Party Advisory |
Track CVE-2021-46065 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-46065), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.