← Vulnerability feed

Vulnerability record · CVE-2021-46065 · published 27 January 2022

CVE-2021-46065: Zoho ManageEngine ServiceDesk Plus secondary email field XSS

Zohocorp · Manageengine Servicedesk Plus

A stored cross-site scripting flaw exists in the Secondary Email field of Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306, allowing injection of arbitrary JavaScript. Because the field is rendered to other users, injected script can run in their browsers within the application context.

4.8 CVSS 3.1 Medium EPSS 92% · top 0.2% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score, v2 3.5
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityCVSS rates it medium (4.8) and it requires high privileges plus user interaction, though public exploit code and very high EPSS raise concern.

What it is

A stored cross-site scripting flaw exists in the Secondary Email field of Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306, allowing injection of arbitrary JavaScript. Because the field is rendered to other users, injected script can run in their browsers within the application context.

Impact

An attacker can execute arbitrary JavaScript in the browser of a user viewing the affected field, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reached over the network through the application's web interface. The vector requires high privileges (PR:H) and user interaction (UI:R), so an authenticated high-privilege user must enter the payload and a victim must view the affected field.

Exploitation

No CISA KEV listing, but EPSS is very high (0.91737, 99.81st percentile) and public exploit references are tagged Exploit, indicating known public proof-of-concept code. No ransomware association is documented.

What to do

  • Apply the vendor fix referenced in the ManageEngine ServiceDesk Plus release notes and upgrade beyond Build 11306.
  • Restrict access to the ServiceDesk Plus web interface to trusted networks and limit high-privilege accounts.
  • Validate and sanitize or encode the Secondary Email field on input and output.
  • Deploy a web application firewall or content security policy to reduce script execution impact.

Detection

  • Search application and web logs for script tags or JavaScript payloads submitted to the Secondary Email field.
  • Monitor for anomalous requests to ServiceDesk Plus endpoints containing encoded script content.
  • Review accounts with high privileges for unexpected changes to email or profile fields.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-46065 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-44077Zoho ManageEngine ServiceDesk Plus unauthenticated RCEZoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling…KEVEPSS 93%analysed9.8CVE-2021-37415Zoho ManageEngine ServiceDesk Plus authentication bypass via REST APIZoho ManageEngine ServiceDesk Plus before build 11302 contains an authentication bypass (CWE-306) that lets a small number of REST-API URLs be reache…KEVEPSS 100%analysed6.5CVE-2019-8394Zoho ManageEngine ServiceDesk Plus unrestricted file upload via login page customizationZoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization fe…KEVEPSS 63%analysed9.8CVE-2021-44526Zohocorp manageengine servicedesk plus vulnerabilityZoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.EPSS 3.2%9.8CVE-2019-8395Zohocorp manageengine servicedesk plus path traversal vulnerabilityAn Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment…EPSS 7.1%8.8CVE-2020-35682Zohocorp manageengine servicedesk plus incorrect authorization vulnerabilityZoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).EPSS 7.2%8.8CVE-2017-9362Zohocorp manageengine servicedesk plus xml external entity (xxe) vulnerabilityManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2021-46065), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.