CVE-2018-17283

HIGH EXPLOITED NUCLEI

Zoho ManageEngine OpManager <12.3 Build 123196 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-17283 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.

Nuclei Templates (1)

Zoho ManageEngine OpManager - SQL Injection
HIGHVERIFIEDby DhiyaneshDK
Shodan: http.title:"OpManager"
FOFA: title="OpManager"

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/x-f1v3/ForCve/issues/4

Scores

CVSS v3 7.5
EPSS 0.6010
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2024-01-06
CWE
CWE-89
Status published
Products (1)
zohocorp/manageengine_opmanager < 12.3
Published Sep 21, 2018
Tracked Since Feb 18, 2026