CVE-2022-40300
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2022-40300 identifies multiple SQL injection vulnerabilities in Zoho ManageEngine Password Manager Pro versions before 12121, PAM360 versions before 5600, and Access Manager Plus versions before 4305. An attacker can exploit these vulnerabilities by injecting malicious SQL statements into input fields, potentially leading to unauthorized data access, modification, or disclosure. The vulnerabilities could put sensitive information at risk and allow attackers to gain unauthorized system access. It is strongly recommended that affected organizations apply the necessary patches to mitigate these risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- ManageEngine Password Manager Pro
- Zohocorp Manageengine Pam360
Affected Vendors
- Zoho Corporation