Impact
The vulnerability allows an attacker with valid credentials to inject arbitrary SQL into the database of ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552. This authenticated SQL injection can result in the disclosure, alteration, or deletion of sensitive data stored by the applications. The weakness is classified as CWE‑89 and poses direct risk to database integrity and confidentiality. As the exploitation requires an authenticated session, it does not grant arbitrary code execution but enables attackers to manipulate sensitive records.
Affected Systems
Affected systems include Zohocorp’s ManageEngine Password Manager Pro and ManageEngine PAM360. Versions prior to 13232 of Password Manager Pro and prior to 8552 of PAM360 are susceptible. All installations of these products before the indicated release numbers must be reviewed and remediated.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity assessment, while the EPSS score is not available, indicating no current published exploitation data. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to possess legitimate user credentials; thus the exploitation is more probable against accounts with elevated privileges. Once authenticated, the injection can be performed via exposed user input fields or API endpoints that construct SQL queries insecurely.
OpenCVE Enrichment