Security readout for executives and security teams
Plain-English summary
This is a stored cross-site scripting issue in Zoho ManageEngine Applications Manager versions before build 15130. If malicious Active Directory user details are imported, attacker-controlled script content could be stored and later displayed to application users. The provided sources do not show active exploitation or a CVSS score.
Executive priority
Prioritize remediation for internet-accessible, administrator-facing, or AD-integrated deployments. The issue is not confirmed as actively exploited in the provided sources, but stored XSS in an operations platform can create business risk if administrators view hostile stored content.
Technical view
CVE-2021-31813 affects Zoho ManageEngine Applications Manager before 15130 during import of malicious user details from AD, including crafted user names. The source bundle identifies stored XSS but does not provide CWE, CVSS, authentication context, privilege requirements, or browser execution scope.
Likely exposure
Exposure is most likely where Zoho ManageEngine Applications Manager is below build 15130 and imports user details from Active Directory. The affected product metadata in the bundle is incomplete, so validation should focus on installed build numbers and AD import workflows.
Exploitation context
The CVE is not listed as CISA KEV in the provided bundle. Public references include the vendor advisory and a Raxis write-up, but the bundle does not establish observed exploitation in the wild. Treat this as a credible stored XSS risk with incomplete severity data.
Researcher notes
Key gaps are missing CVSS, CWE, exploit prerequisites, affected CPEs, and detailed fixed-version evidence beyond “before 15130.” Validation should avoid assuming exploitability across unrelated ManageEngine products. Use the vendor advisory and Raxis reference for confirmation.
Mitigation direction
- Upgrade Zoho ManageEngine Applications Manager to build 15130 or later.
- Review the vendor security update before scheduling remediation.
- Restrict access to Applications Manager administration interfaces.
- Review AD import sources for unexpected or untrusted user data.
- Monitor vendor guidance for any revised severity or remediation details.
Validation and detection
- Inventory all ManageEngine Applications Manager instances and build numbers.
- Confirm whether each instance imports user details from Active Directory.
- Verify upgraded systems report build 15130 or later.
- Review recent AD imports for unusual crafted display names or usernames.
- Check application logs for suspicious activity around user import workflows.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-31813 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2021-31813.htmlCVE reference · x_refsource_MISC
- https://raxis.com/blog/cve-2021-31813CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
