CVE-2022-40300

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 16, 2022
Updated: Jan 13, 2025
CWE ID 89

Summary

CVE-2022-40300 identifies multiple SQL injection vulnerabilities in Zoho ManageEngine Password Manager Pro versions before 12121, PAM360 versions before 5600, and Access Manager Plus versions before 4305. An attacker can exploit these vulnerabilities by injecting malicious SQL statements into input fields, potentially leading to unauthorized data access, modification, or disclosure. The vulnerabilities could put sensitive information at risk and allow attackers to gain unauthorized system access. It is strongly recommended that affected organizations apply the necessary patches to mitigate these risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • ManageEngine Password Manager Pro
  • Zohocorp Manageengine Pam360

Affected Vendors

  • Zoho Corporation