SQL Injection Vulnerabilities in ManageEngine Password Manager Pro
CVE-2014-8499
Currently unrated
Summary
Multiple vulnerabilities exist in ManageEngine Password Manager Pro and its Managed Service Providers edition that permit remote authenticated users to execute arbitrary SQL commands through the SEARCH_ALL parameter. Specifically, these flaws are located in the SQLAdvancedALSearchResult.cc and AdvancedSearchResult.cc files. Exploiting these vulnerabilities can lead to unauthorized access to sensitive data and compromise the integrity of the database.
References
EPSS Score
77% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved