← Back

CVE-2015-7766

nvd nist
Published: Oct 9, 2015Modified: May 6, 2026

JSON object

Loading...
9.0
Vector
AV:N/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 8.0 / Impact: 10.0
Source: NVD

Description

PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."

Affected (2)

1 product
Manageengine Opmanager
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Up to 11.5
Version 11.6

Related CWEs

Timeline

No history available yet.