← Back to CVE List

CVE-2019-11448

Published: 2019-04-22T11:29Z
Last Modified: 2024-11-21T04:21Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt