CVE-2020-35765: Zohocorp ManageEngine Applications Manager

High severity, CVSS 8.8. EPSS: 27.3% chance of exploitation in the next 30 days.

doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.

Affected products

  • Zohocorp ManageEngine Applications Manager: before 14.9 (fixed in 14.9); version 14.9 only

Published 2021-02-05. Last modified 2026-06-17.