CVE-2019-12196

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
05/06/2019
Last modified:
07/06/2019

Description

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.3:*:*:*:*:*:*:*