VYPR
Unrated severityNVD Advisory· Published Oct 29, 2020· Updated Aug 4, 2024

CVE-2020-27995

CVE-2020-27995

Description

SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated SQL injection in Zoho ManageEngine Applications Manager before 14560 allows remote command execution via the MyPage.do template_resid parameter.

Vulnerability

Zoho ManageEngine Applications Manager versions before 14560 contain a SQL injection vulnerability in the MyPage.do endpoint. The template_resid parameter is not properly sanitized, allowing an attacker to inject arbitrary SQL commands. The vulnerability is reachable without authentication due to the design of the affected page. [1]

Exploitation

An attacker with network access to the server can send a crafted HTTP request to the MyPage.do endpoint with a malicious value in the template_resid parameter. No authentication or special privileges are required. The injected SQL payload can be leveraged to execute operating system commands on the database server, which in this application architecture can lead to command execution on the application server. [1]

Impact

Successful exploitation allows an attacker to execute arbitrary commands on the server, potentially leading to full compromise of the application and underlying system. This includes data exfiltration, modification, or destruction, as well as lateral movement within the network. The impact is considered critical due to the lack of authentication required and the high privileges achievable. [1]

Mitigation

Zoho has released version 14560 of ManageEngine Applications Manager, which fixes this vulnerability. Users should upgrade to version 14560 or later immediately. No workarounds are available for unpatched versions. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.