CVE Published: 09/04/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: tenable |
Vendor: n/a |
Product: ManageEngine ServiceDesk Plus Status : PUBLISHED
CVE-2021-20080 Description
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.