First published: Sun Nov 05 2017(Updated: )
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Applications Manager | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16542 has a moderate severity rating due to its potential for post-authentication SQL injection.
To fix CVE-2017-16542, upgrade to Zoho ManageEngine Applications Manager version 13 build 13500 or later.
The impact of CVE-2017-16542 could allow attackers to execute arbitrary SQL commands on the database.
CVE-2017-16542 affects Zoho ManageEngine Applications Manager version 13.0 before build 13500.
CVE-2017-16542 occurs due to insufficient input validation in the name parameter during an insert operation via POST requests.