Impact
ManageEngine DataSecurity Plus versions earlier than 6310 contain an authenticated SQL injection flaw in the Reports module. An attacker who can authenticate as a technician can inject and execute arbitrary SQL statements against the underlying database, potentially retrieving sensitive data, modifying records, or executing database commands that may lead to further compromise. This weakness is a classic example of CWE‑89.
Affected Systems
The vulnerable scope is the ManageEngine DataSecurity Plus product from Zohocorp, specifically all releases prior to 6310 regardless of installation platform. Any deployment that uses the Reports module and accepts technician‑level credentials is affected.
Risk and Exploitability
The CVSS score of 7.7 indicates a high risk potential, and the EPSS score of 1.5% indicates exploitation is plausible but not extremely common. Because the attack requires authenticated access, the vulnerability is not exploitable by unauthenticated users, and it is not listed in CISA’s KEV catalog. The overall threat level remains high for environments where technician credentials are accessible or have not been properly secured.
OpenCVE Enrichment