CVE-2018-15168: Zohocorp ManageEngine Applications Manager

Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.

A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.

Affected products

  • Zohocorp ManageEngine Applications Manager: before 13.13820 (fixed in 13.13820)

Published 2018-08-08. Last modified 2026-06-17.