ZeroHour

CVE-2021-40493

CVSS 3.1
9.8 critical
EPSS
50%p99
Published
()
Modified
Description

Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.

Vendors
zohocorp
Products
manageengine opmanager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.