Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
Source: 0fc0942c-577d-436f-ae8e-945763c79b02
Type: Secondary
Exploitability Score: 2.8
Impact Score: 5.9
| Source | Type | Description |
|---|---|---|
| 0fc0942c-577d-436f-ae8e-945763c79b02 | Secondary |
en
CWE-89
|