CVE-2024-6748

EUVD-2024-47785
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
zohocorpmanageengine_opmanager
𝑥
≤ 128317
ADP
zohocorpmanageengine_opmanager_plus
𝑥
≤ 128317
ADP
zohocorpmanageengine_opmanager_msp
𝑥
≤ 128317
ADP
zohocorpmanageengine_opmanager_rmm
𝑥
≤ 128317
ADP