ZeroHour

CVE-2020-35765

PoC
CVSS 3.1
8.8 high
EPSS
27%p98
Published
()
Modified
Description

doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.

Vendors
zohocorp
Products
manageengine applications manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.