LiveActive security incident?Get immediate response
CVE Record

CVE-2021-33256: A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No:...

A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This CVE describes a disputed CSV injection issue in ManageEngine ADSelfService Plus 6.1 build 6101. An unauthenticated login attempt could place malicious spreadsheet content into an audit CSV, creating risk when a privileged user exports and opens that report.

Executive priority

Handle as a moderate governance and exposure-review item unless local evidence shows the workflow is common or privileged users open these CSVs in formula-evaluating spreadsheets. The vendor dispute and missing severity data reduce confidence.

Technical view

The reported input is the login panel's j_username parameter. The described impact depends on later export of the User Attempts Audit Report as CSV and spreadsheet evaluation by a privileged user. CVSS, CWE, and official affected CPE data are not provided.

Likely exposure

Exposure appears limited to organizations using the named ADSelfService Plus version/build and operationally exporting login-attempt audit reports to CSV. Evidence is incomplete because the CVE affected-product fields are generic and the vendor disputes validity.

Exploitation context

The source bundle does not show CISA KEV listing or active exploitation evidence. The described scenario is a chained, user-interaction-dependent CSV injection rather than direct server compromise, although the report claims severe consequences if opened by a privileged user.

Researcher notes

Key uncertainty is product-side responsibility: the vendor reportedly disputes this as not a valid ADSSP vulnerability. Focus validation on whether untrusted login input reaches CSV output unsanitized and whether privileged spreadsheet execution is realistic in the environment.

Mitigation direction

  • Check ManageEngine guidance for the current vendor position and any related updates.
  • Restrict audit CSV exports to trusted administrators while assessing exposure.
  • Treat exported login audit CSV files as untrusted input.
  • Open audit exports only in tools configured not to evaluate formulas.
  • Review whether affected build 6101 remains deployed.

Validation and detection

  • Inventory ADSelfService Plus deployments and confirm exact version and build.
  • Identify who can export User Attempts Audit Report CSV files.
  • Review login-attempt audit data for suspicious spreadsheet formula prefixes.
  • Confirm spreadsheet handling policies for security-sensitive CSV exports.
  • Document vendor dispute status in the risk record.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-33256 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.