CVE-2024-6748

EUVD-2024-47785
Zohocorp ManageEngineĀ OpManager, OpManager Plus, OpManager MSP and RMM versionsĀ 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
ManageEngineCNA
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L