Critical severity9.8NVD Advisory· Published Nov 5, 2017· Updated May 13, 2026
CVE-2017-16543
CVE-2017-16543
Description
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
Affected products
1- cpe:2.3:a:zohocorp:manageengine_applications_manager:13.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/43129/nvdExploitThird Party AdvisoryVDB Entry
- code610.blogspot.com/2017/11/sql-injection-in-manageengine.htmlnvdThird Party Advisory
- www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2017-16543.htmlnvd
News mentions
0No linked articles in our index yet.