CVE-2020-35765

EUVD-2020-23421
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_applications_manager
𝑥
< 14.9
zohocorpmanageengine_applications_manager
14.9
zohocorpmanageengine_applications_manager
14.9:build14900
zohocorpmanageengine_applications_manager
14.9:build14910
zohocorpmanageengine_applications_manager
14.9:build14911
zohocorpmanageengine_applications_manager
14.9:build14930
𝑥
= Vulnerable software versions