CVE-2017-16851: SQL Injection
Published Nov 16, 2017
·Updated
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
Affected Software
1 affected component
ZohoCorp ManageEngine Applications Manager=13.0
Event History
Nov 16, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2017-16851?
CVE-2017-16851 is a vulnerability in Zoho ManageEngine Applications Manager 13 before build 13530 that allows SQL injection via the /MyPage.do widgetid parameter.
2
How severe is CVE-2017-16851?
CVE-2017-16851 has a severity rating of 9.8 (critical).
3
How does CVE-2017-16851 affect Zoho ManageEngine Applications Manager?
CVE-2017-16851 affects Zoho ManageEngine Applications Manager 13 before build 13530.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2017-16851?
The CWE ID for CVE-2017-16851 is CWE-89.
5
How do I fix CVE-2017-16851?
To fix CVE-2017-16851, users should update to Zoho ManageEngine Applications Manager build 13530 or a later version.