CVE-2020-27995
Description
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated SQL injection in Zoho ManageEngine Applications Manager before 14560 allows remote command execution via the MyPage.do template_resid parameter.
Vulnerability
Zoho ManageEngine Applications Manager versions before 14560 contain a SQL injection vulnerability in the MyPage.do endpoint. The template_resid parameter is not properly sanitized, allowing an attacker to inject arbitrary SQL commands. The vulnerability is reachable without authentication due to the design of the affected page. [1]
Exploitation
An attacker with network access to the server can send a crafted HTTP request to the MyPage.do endpoint with a malicious value in the template_resid parameter. No authentication or special privileges are required. The injected SQL payload can be leveraged to execute operating system commands on the database server, which in this application architecture can lead to command execution on the application server. [1]
Impact
Successful exploitation allows an attacker to execute arbitrary commands on the server, potentially leading to full compromise of the application and underlying system. This includes data exfiltration, modification, or destruction, as well as lateral movement within the network. The impact is considered critical due to the lack of authentication required and the high privileges achievable. [1]
Mitigation
Zoho has released version 14560 of ManageEngine Applications Manager, which fixes this vulnerability. Users should upgrade to version 14560 or later immediately. No workarounds are available for unpatched versions. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho/ManageEngine Applications Managerdescription
- Range: <14560
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.manageengine.com/products/applications_manager/issues.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.