First published: Fri Oct 09 2015(Updated: )
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine OpManager MSP | <=11.5 | |
ManageEngine OpManager MSP | =11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7766 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2015-7766, upgrade ManageEngine OpManager to the latest version that addresses this vulnerability.
ManageEngine OpManager versions 11.5 and earlier, as well as version 11.6, are affected by CVE-2015-7766.
CVE-2015-7766 allows an attacker to bypass SQL query restrictions, enabling potential remote code execution.
Remote administrators of ManageEngine OpManager can be impacted by CVE-2015-7766 if they do not apply the necessary patches.