CVE-2018-15168: SQL Injection
Published Aug 8, 2018
·Updated
A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
Affected Software
1 affected component
ZohoCorp ManageEngine Applications Manager<13.13820
Event History
Aug 8, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-15168?
The severity of CVE-2018-15168 is critical with a score of 9.8.
2
How does the SQL Injection vulnerability in CVE-2018-15168 work?
The SQL Injection vulnerability in CVE-2018-15168 can be exploited through the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
3
What software is affected by CVE-2018-15168?
The Zoho ManageEngine Applications Manager version 13 before build 13820 is affected by CVE-2018-15168.
4
Is there a fix available for CVE-2018-15168?
Yes, a fix is available. Please refer to the vendor's security update page for more information.
5
Where can I find more information about CVE-2018-15168?
You can find more information about CVE-2018-15168 on the vendor's security updates page and the CVE details page.