CVE-2024-5546

HIGH

ManageEngine PAM360 < 7001 - Authenticated SQL Injection via Global Search Option

Title source: llm
STIX 2.1

Description

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.

References (1)

Core 1

Scores

CVSS v3 8.3
EPSS 0.0122
EPSS Percentile 79.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (15)
zohocorp/manageengine_pam360 4.0 (3 CPE variants)
zohocorp/manageengine_pam360 4.1 (3 CPE variants)
zohocorp/manageengine_pam360 4.5 (3 CPE variants)
zohocorp/manageengine_pam360 5.0 (6 CPE variants)
zohocorp/manageengine_pam360 5.1 (2 CPE variants)
zohocorp/manageengine_pam360 5.2 (2 CPE variants)
zohocorp/manageengine_pam360 5.3 (8 CPE variants)
zohocorp/manageengine_pam360 5.4 build5400 (2 CPE variants)
zohocorp/manageengine_pam360 5.5 build5500 (4 CPE variants)
zohocorp/manageengine_pam360 5.7 build5700 (5 CPE variants)
... and 5 more
Published Aug 28, 2024
Tracked Since Feb 18, 2026