CVE-2021-41288
Severity
9.8CRITICAL
EPSS
32.5%
top 3.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 30
Latest updateDec 11
Description
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages1 packages
๐ดVulnerability Details
2๐Detection Rules
1Suricataโถ
ET WEB_SPECIFIC_APPS Zoho ManageEngine OpManager getReportData SQL Injection (CVE-2021-41288)โ2025-12-11