Impact
ZohoCorp ManageEngine Applications Manager versions 182000 and older suffered from a SQL injection flaw that could be exploited by a low-privileged user. The vulnerability allows the attacker to execute arbitrary SQL commands, which can lead to privilege escalation, granting full administrator rights and potentially remote code execution on the system. This constitutes a serious breach of confidentiality, integrity, and availability of the managed infrastructure.
Affected Systems
The affected product is Zohocorp ManageEngine Applications Manager, specifically releases 182000 and below. No other versions or related modules are listed as impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity and the lack of an EPSS score means current exploitation probability is unknown. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector involves a web interface or API that accepts unsanitized input, enabling an attacker with minimal privileges to craft malicious SQL payloads and thereby gain unrestricted access.
OpenCVE Enrichment