Zoho ManageEngine Applications Manager CVE-2019-11448 SQL Injection Vulnerability
BID:108560
Info
Zoho ManageEngine Applications Manager CVE-2019-11448 SQL Injection Vulnerability
| Bugtraq ID: | 108560 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-11448 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2019 12:00AM |
| Updated: | Apr 24 2019 12:00AM |
| Credit: | AKKUS. |
| Vulnerable: |
Zoho ManageEngine Applications Manager 14.0 Zoho ManageEngine Applications Manager 13.9 Zoho ManageEngine Applications Manager 13.8 Zoho ManageEngine Applications Manager 13.7 Zoho ManageEngine Applications Manager 13.6 Zoho ManageEngine Applications Manager 13.5 Zoho ManageEngine Applications Manager 13.4 Zoho ManageEngine Applications Manager 13.3 Zoho ManageEngine Applications Manager 13.2 Zoho ManageEngine Applications Manager 13.1 Zoho ManageEngine Applications Manager 13 Zoho ManageEngine Applications Manager 12.9 Zoho ManageEngine Applications Manager 12.8 Zoho ManageEngine Applications Manager 12.7 Zoho ManageEngine Applications Manager 12.6 Zoho ManageEngine Applications Manager 12.5 Zoho ManageEngine Applications Manager 12.4 Zoho ManageEngine Applications Manager 12.3 Zoho ManageEngine Applications Manager 12.2 Zoho ManageEngine Applications Manager 12.1 Zoho ManageEngine Applications Manager 12.0 Zoho ManageEngine Applications Manager 11.9 Zoho ManageEngine Applications Manager 11.8 Zoho ManageEngine Applications Manager 11.7 Zoho ManageEngine Applications Manager 11.6 Zoho ManageEngine Applications Manager 11.5 Zoho ManageEngine Applications Manager 11.4 Zoho ManageEngine Applications Manager 11.3 Zoho ManageEngine Applications Manager 11.2 Zoho ManageEngine Applications Manager 11.1 Zoho ManageEngine Applications Manager 11.0 |
| Not Vulnerable: |
Zoho ManageEngine Applications Manager 14.1 |
Discussion
Zoho ManageEngine Applications Manager CVE-2019-11448 SQL Injection Vulnerability
Zoho ManageEngine Applications Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker may leverage this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ManageEngine Applications Manager 11.0 through 14.0 are vulnerable; other versions may also be affected.
Zoho ManageEngine Applications Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker may leverage this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ManageEngine Applications Manager 11.0 through 14.0 are vulnerable; other versions may also be affected.
Exploit / POC
Zoho ManageEngine Applications Manager CVE-2019-11448 SQL Injection Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Zoho ManageEngine Applications Manager CVE-2019-11448 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Zoho ManageEngine Applications Manager CVE-2019-11448 SQL Injection Vulnerability
References:
References: