CVE-2020-35765

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
05/02/2021
Last modified:
17/02/2021

Description

doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:* 14.9 (excluding)
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:-:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:build14900:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:build14910:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:build14911:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_applications_manager:14.9:build14930:*:*:*:*:*:*