CVE-2015-7766
HIGH 9.0EPSS 80.6%
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."
- CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 80.64% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2015-10-09
- Updated
- 2024-09-17