CVE-2014-8498
SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 12.75% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- zohocorp/manageengine password manager pro
- Source
- cve@mitre.org
References
- http://osvdb.org/show/osvdb/114483Broken Link
- http://packetstormsecurity.com/files/129036/Password-Manager-Pro-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2014/Nov/18Exploit, Mailing List, Third Party Advisory
- http://www.exploit-db.com/exploits/35210Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/71016Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98596VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_pmp_privesc.txtExploit
- http://osvdb.org/show/osvdb/114483Broken Link
- http://packetstormsecurity.com/files/129036/Password-Manager-Pro-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2014/Nov/18Exploit, Mailing List, Third Party Advisory
- http://www.exploit-db.com/exploits/35210Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/71016Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98596VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_pmp_privesc.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.