CVE-2018-15168: Zohocorp ManageEngine Applications Manager
Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.
A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
Affected products
- Zohocorp ManageEngine Applications Manager: before 13.13820 (fixed in 13.13820)
Published 2018-08-08. Last modified 2026-06-17.