High severity8.8NVD Advisory· Published Nov 5, 2017· Updated May 13, 2026
CVE-2017-16542
CVE-2017-16542
Description
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
Affected products
1- cpe:2.3:a:zohocorp:manageengine_applications_manager:13.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/43129/nvdExploitThird Party AdvisoryVDB Entry
- code610.blogspot.com/2017/11/sql-injection-in-manageengine.htmlnvdThird Party Advisory
- www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2017-16542.htmlnvd
News mentions
0No linked articles in our index yet.