CVE-2018-17283
Zoho manageengine_opmanager Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2018-17283 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 6, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
manageengine_opmanagerBrowse Zoho / manageengine_opmanager | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHZoho ManageEngine OpManager - SQL InjectionCVSS 7.5
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.
Impact
Unauthenticated attackers can execute SQL injection attacks to access or modify database contents, add administrator users, or extract sensitive information including credentials.
Remediation
Upgrade to ManageEngine OpManager version 12.3 Build 123196 or later.
Source: ProjectDiscovery