CVE-2017-16543

Publication date

2017-11-05 17:00:00

Family

mitre

State

PUBLISHED

Description

Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.