ManageEngine Analytics Plus
cpe:2.3:a:zohocorp:manageengine_analytics_plus:*:*:*:*:*:*:*
- < 6171
A SQL injection vulnerability has been identified in ManageEngine Analytics Plus on-premise versions through 6171. This vulnerability allows authenticated users to execute arbitrary SQL queries via the key update API, due to insufficient input validation. Exploitation of this vulnerability could lead to unauthorized access, data manipulation, or disruption of the database.
Exploitation of this vulnerability could allow authenticated users to execute arbitrary SQL queries, potentially leading to unauthorized access, manipulation of data, or disruption of the database.
Users can upgrade to the latest version by downloading the upgrade pack from the ManageEngine Analytics Plus service pack page and following the provided upgrade instructions. For support, contact the ManageEngine Analytics Plus support team via email.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.