Medium severity5.4NVD Advisory· Published Jun 7, 2021· Updated Jun 17, 2026
CVE-2021-28382
CVE-2021-28382
Description
Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:zohocorp:manageengine_key_manager_plus:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:*:*:*:*:*:*:*:*range: <6.0
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.0:6000:*:*:*:*:*:*
- Zoho/ManageEngine Key Manager Plusdescription
- Range: <6001
- Range: <6001
Patches
Vulnerability mechanics
References
2- raxis.com/blog/cve-2021-28382nvdExploitThird Party Advisory
- www.manageengine.com/key-manager/release-notes.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.