EIP-2026-102408
PRE-CVEManagEnegine ADManager Plus 6.5.40 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102408. PoCs published by Mehmet Ince.
AI-analyzed exploit summary The exploit demonstrates an authenticated second-order SQL injection vulnerability in ManageEngine ADManager Plus <= 6.5.40, where user-controlled parameters are directly used in SQL queries without validation. It also includes multiple reflected XSS vulnerabilities across various endpoints.
Description
ManagEnegine ADManager Plus 6.5.40 - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates an authenticated second-order SQL injection vulnerability in ManageEngine ADManager Plus <= 6.5.40, where user-controlled parameters are directly used in SQL queries without validation. It also includes multiple reflected XSS vulnerabilities across various endpoints.