CVE-2022-27908

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGH
EPSS
7.3%
top 8.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateApr 19

Description

Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xcxp-75xq-4wfj: Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module2022-04-19
CVEList
CVE-2022-27908: Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module2022-04-18
CVE-2022-27908 (HIGH CVSS 8.8) | Zoho ManageEngine OpManager before | cvebase.io