SQL Injection Vulnerability in ManageEngine Applications Manager by Zoho
CVE-2020-15927
8.8HIGH
What is CVE-2020-15927?
An SQL Injection vulnerability exists in Zoho's ManageEngine Applications Manager versions up to and including 14740. This vulnerability allows an authenticated attacker to manipulate SQL queries via a specially crafted JSP request within the SAP module. If exploited, this could lead to unauthorized data access and potential data manipulation.