CVE-2024-5546

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGH
EPSS
1.2%
top 20.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 28

Description

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:LExploitability: 2.8 | Impact: 5.5

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-9hmf-r3fq-947x: Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Inject2024-08-28
CVEList
SQL Injection2024-08-28
CVE-2024-5546 (HIGH CVSS 8.8) | Zohocorp ManageEngine Password Mana | cvebase.io