Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_adselfservice_plus | 6.1-6100 | 6.1-6100.x |
| zohocorp / manageengine_adselfservice_plus | 6.1-6103 | 6.1-6103.x |
| zohocorp / manageengine_adselfservice_plus | 6.1 | 6.1.x |
| zohocorp / manageengine_adselfservice_plus | - | 6.1 |