CVE-2020-35765

doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
zohocorpmanageengine_applications_manager
𝑥
< 14.9
zohocorpmanageengine_applications_manager
14.9
zohocorpmanageengine_applications_manager
14.9:build14900
zohocorpmanageengine_applications_manager
14.9:build14910
zohocorpmanageengine_applications_manager
14.9:build14911
zohocorpmanageengine_applications_manager
14.9:build14930
𝑥
= Vulnerable software versions