CVE-2019-11448: Zohocorp ManageEngine Applications Manager
Critical severity, CVSS 9.8. EPSS: 12.4% chance of exploitation in the next 30 days.
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.
Affected products
- Zohocorp ManageEngine Applications Manager: from 11.0, up to and including 14.0
Published 2019-04-22. Last modified 2026-06-17.