VYPR
Unrated severityNVD Advisory· Published Jan 19, 2021· Updated Aug 4, 2024

CVE-2020-27733

CVE-2020-27733

Description

Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authenticated SQL injection in Zoho ManageEngine Applications Manager before build 14880 allows crafted Alarmview requests to extract database contents.

Vulnerability

An SQL injection vulnerability exists in Zoho ManageEngine Applications Manager prior to version 14 build 14880. The flaw is triggered via a specially crafted Alarmview request, which is accessible to authenticated users. No additional configuration is required beyond default settings. [1][2]

Exploitation

An attacker must first obtain a valid authenticated session for the Applications Manager web interface. Once authenticated, the attacker sends a malicious Alarmview request containing SQL metacharacters in a parameter. The injection allows the attacker to manipulate the underlying SQL query executed by the application. [1]

Impact

Successful exploitation enables the attacker to read, modify, or delete arbitrary data from the backend database, potentially exposing sensitive information such as application credentials, user data, or system configuration. The attacker operates within the context of the application's database user. [1]

Mitigation

The vulnerability is fixed in ManageEngine Applications Manager version 14 build 14880, released by the vendor on an unknown date. Users should upgrade to this build or later. No workarounds are documented, and this CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing. [1][2]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.