vendor:
Applications Manager
by:
aldorm
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Applications Manager
Affected Version From: 12
Affected Version To: 13 before Build 13200
Patch Exists: YES
Related CWE: CVE-2016-9488
CPE: a:manageengine:applications_manager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
ManageEngine Applications Manager 13 – ‘MenuHandlerServlet’ SQL Injection
ManageEngine Applications Manager 12 and 13 before Build 13200 are vulnerable to a SQL Injection vulnerability in the MenuHandlerServlet servlet. An attacker can exploit this vulnerability to extract all users and passwords from the database, as well as create new users with administrative privileges.
Mitigation:
Upgrade to the latest version of ManageEngine Applications Manager 13 Build 13200 or later.