VYPR
Unrated severityNVD Advisory· Published Jul 17, 2021· Updated Aug 4, 2024

CVE-2021-36772

CVE-2021-36772

Description

Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated stored XSS in Zoho ManageEngine ADManager Plus before build 7110 allows an attacker to inject arbitrary JavaScript in report configuration fields.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in Zoho ManageEngine ADManager Plus before build 7110 [1]. The bug allows an authenticated user to inject arbitrary HTML or JavaScript into report configuration fields, which is then stored and executed when other users view the affected reports. Affected versions are all builds prior to 7110.

Exploitation

An attacker must be an authenticated user with permission to modify report configurations. The attacker crafts a payload containing malicious JavaScript and saves it in a report configuration field. When an administrator or any other user with access to the report views the stored configuration, the payload executes in the context of the victim's browser session. No additional user interaction beyond viewing the report is required once the payload is stored.

Impact

Successful exploitation leads to arbitrary JavaScript execution within the victim's browser session within the application's context. The attacker can perform actions on behalf of the victim, such as modifying configurations, exfiltrating sensitive data displayed in the application (e.g., user attributes, group memberships), or performing administrative actions if the victim is a privileged user.

Mitigation

The vulnerability is fixed in ManageEngine ADManager Plus build 7110 and later [1]. Administrators should upgrade to build 7110 or any subsequent build. There is no known workaround, and the vendor released the fix as part of a security update.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.