CVE-2018-20173 — SQL Injection in Manageengine Opmanager
Severity
9.8CRITICALNVD
EPSS
12.8%
top 5.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 17
Latest updateDec 11
Description
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9