CVE-2019-11469: SQL Injection
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11469?
CVE-2019-11469 is a vulnerability in Zoho ManageEngine Applications Manager 12 through 14 that allows SQL injection and unauthorized file upload.
How severe is CVE-2019-11469?
CVE-2019-11469 is considered a critical vulnerability with a severity value of 9.8.
What software is affected by CVE-2019-11469?
Zoho ManageEngine Applications Manager versions 12 through 14 are affected by CVE-2019-11469.
How can an unauthenticated user exploit CVE-2019-11469?
An unauthenticated user can exploit CVE-2019-11469 by uploading a malicious file via the "Execute Program Action(s)" feature, gaining the authority of SYSTEM on the server.
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-11469?
The Common Weakness Enumeration (CWE) ID for CVE-2019-11469 is CWE-89, which refers to a SQL injection vulnerability.