First published: Mon Apr 22 2019(Updated: )
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Applications Manager | >=11.0<=14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-11448.
The severity of CVE-2019-11448 is critical with a severity value of 9.8.
An unauthenticated user can exploit this vulnerability through a Popup_SLA.jsp sid SQL injection.
If an attacker exploits CVE-2019-11448, they can gain the authority of SYSTEM on the server and write arbitrary text to a .vbs file.
Yes, there are several references available for CVE-2019-11448, including: https://pentest.com.tr/exploits/ManageEngine-App-Manager-14-SQLi-Remote-Code-Execution.html, https://www.exploit-db.com/exploits/46725