Vulnerabilities > Zohocorp > Manageengine Applications Manager > 14.9

DATE CVE VULNERABILITY TITLE RISK
2024-08-01 CVE-2024-5678 SQL Injection vulnerability in Zohocorp Manageengine Applications Manager
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
network
low complexity
zohocorp CWE-89
4.7
2023-08-10 CVE-2023-38333 Cross-site Scripting vulnerability in Zohocorp Manageengine Applications Manager
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
network
low complexity
zohocorp CWE-79
6.1
2023-04-26 CVE-2023-29442 Cross-site Scripting vulnerability in Zohocorp Manageengine Applications Manager
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
network
low complexity
zohocorp CWE-79
6.1
2023-04-11 CVE-2023-28340 XXE vulnerability in Zohocorp Manageengine Applications Manager
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
network
low complexity
zohocorp CWE-611
6.5
2021-07-01 CVE-2021-31813 Cross-site Scripting vulnerability in Zohocorp Manageengine Applications Manager
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
network
low complexity
zohocorp CWE-79
5.4
2021-02-05 CVE-2020-35765 SQL Injection vulnerability in Zohocorp Manageengine Applications Manager
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
network
low complexity
zohocorp CWE-89
8.8