SQL Injection Vulnerability in Zoho ManageEngine Applications Manager
CVE-2020-16267
8.8HIGH
What is CVE-2020-16267?
Zoho ManageEngine Applications Manager, up to version 14740, is susceptible to an SQL Injection vulnerability that allows attackers to execute unauthorized SQL queries through specially crafted JSP requests in the RCA module. This could lead to potential data exposure or manipulation, posing risks to the integrity and confidentiality of sensitive information stored within the application. It is essential for users to apply the latest security updates to mitigate any risks associated with this vulnerability.