CVE-2021-41288
Description
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Pre-authenticated SQL injection in Zoho ManageEngine OpManager's getReportData API on build 125466 and earlier allows unauthenticated remote attackers to extract or modify database content.
Vulnerability
A SQL injection vulnerability exists in the getReportData API of Zoho ManageEngine OpManager build 125466 and earlier [1]. The endpoint fails to properly sanitize user-supplied input before incorporating it into SQL queries, allowing injection of arbitrary SQL statements. No authentication is required to reach the vulnerable API.
Exploitation
An unauthenticated attacker with network access to the affected OpManager instance can send specially crafted HTTP requests to the getReportData API, injecting malicious SQL commands through unsanitized parameters [1]. No special privileges or prior access are needed. The attacker can automate exploitation through repeated requests to enumerate or manipulate database contents.
Impact
Successful exploitation allows the attacker to read, modify, or delete arbitrary data from the underlying database [1]. This can lead to full disclosure of sensitive information, including credentials and configuration data. In some configurations, the attacker may be able to escalate to remote code execution or gain administrative control over the OpManager instance, depending on database permissions [1].
Mitigation
The fix is included in OpManager build 125467 and later [1]. Affected installations must upgrade to build 125467 or newer to remediate the vulnerability. No workaround is provided in the available references; upgrading is the recommended course of action.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho/ManageEngine OpManagerdescription
- Range: <=125466
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.manageengine.com/network-monitoring/help/read-me-complete.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.