VYPR
Unrated severityNVD Advisory· Published Feb 19, 2021· Updated Aug 3, 2024

CVE-2021-27214

CVE-2021-27214

Description

A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An SSRF vulnerability in Zoho ManageEngine ADSelfService Plus through 6013 allows unauthenticated blind HTTP requests or XSS against the admin interface.

Vulnerability

The ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through version 6013 is vulnerable to Server-side Request Forgery (SSRF). A remote unauthenticated attacker can send a crafted HTTP request, resulting in blind HTTP requests from the server or a Cross-site Scripting (XSS) attack against the administrative interface. This issue is distinct from CVE-2019-3905. [1] [2]

Exploitation

An unauthenticated attacker with network access to the ADSelfService Plus server can exploit this by sending a specially crafted HTTP request to the vulnerable servlet. The attack does not require any prior authentication or user interaction, and no special privileges are needed. The attacker can trigger the server to make blind HTTP requests or inject malicious scripts into administrative interface responses.

Impact

Successful exploitation allows the attacker to perform blind HTTP requests (which may access internal resources or exfiltrate data) or conduct reflected/stored XSS attacks against the administrative interface. This can lead to information disclosure, session hijacking, or further compromise of the admin console. [1]

Mitigation

The vendor, Zoho ManageEngine, has addressed this vulnerability in a subsequent build. Affected users should upgrade to the latest version of ADSelfService Plus as indicated in the official release notes. No workarounds have been officially provided. [1]

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.