Back

CVE-2019-11448

CRITICAL

An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.

Published: Apr 22, 2019 Modified: Jun 17, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
zohocorp manageengine_applications_manager * ≥ 11.0

GitHub Security Advisory GHSA-3j3p-jmq2-47r9

An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 12.43%

Top 4% most likely to be exploited

Threat Score 42.9 / 100

Data Sources

NVD EPSS GitHub