CVE-2018-20173: Zohocorp ManageEngine Opmanager

Critical severity, CVSS 9.8. EPSS: 24.5% chance of exploitation in the next 30 days.

Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.

Affected products

  • Zohocorp ManageEngine Opmanager: version 12.3 only

Published 2018-12-17. Last modified 2026-06-17.