VYPR
Unrated severityNVD Advisory· Published Sep 30, 2021· Updated Aug 4, 2024

CVE-2021-41288

CVE-2021-41288

Description

Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Pre-authenticated SQL injection in Zoho ManageEngine OpManager's getReportData API on build 125466 and earlier allows unauthenticated remote attackers to extract or modify database content.

Vulnerability

A SQL injection vulnerability exists in the getReportData API of Zoho ManageEngine OpManager build 125466 and earlier [1]. The endpoint fails to properly sanitize user-supplied input before incorporating it into SQL queries, allowing injection of arbitrary SQL statements. No authentication is required to reach the vulnerable API.

Exploitation

An unauthenticated attacker with network access to the affected OpManager instance can send specially crafted HTTP requests to the getReportData API, injecting malicious SQL commands through unsanitized parameters [1]. No special privileges or prior access are needed. The attacker can automate exploitation through repeated requests to enumerate or manipulate database contents.

Impact

Successful exploitation allows the attacker to read, modify, or delete arbitrary data from the underlying database [1]. This can lead to full disclosure of sensitive information, including credentials and configuration data. In some configurations, the attacker may be able to escalate to remote code execution or gain administrative control over the OpManager instance, depending on database permissions [1].

Mitigation

The fix is included in OpManager build 125467 and later [1]. Affected installations must upgrade to build 125467 or newer to remediate the vulnerability. No workaround is provided in the available references; upgrading is the recommended course of action.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.