← All CVEs

CVE-2014-8498

medium · 6.5

SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.

6.5
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2014-11-17
Published

AV:N/AC:L/Au:S/C:P/I:P/A:P

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
zohocorpmanageengine_password_manager_pro<= 7.1
zohocorpmanageengine_password_manager_pro<= 7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-8498