Zoho ManageEngine NetFlow Analyzer ReportApiHandler compareReport SQL Injection

Strike ID:
E22-7og41
CVSS:
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2019

Description

This strike exploits an SQL injection vulnerability in Zoho ManageEngine NetFlow Analizer. The vulnerability is caused by insufficient validation of parameter DeviceId. Successful exploitation could allow an attacker abilities to execute SQL queries on the target server.

CVE