high · CVSS v3 7.7
CVE-2026-18912
ManageEngine DataSecurity Plus versions prior to 6310 contain an authenticated SQL injection vulnerability in the Reports module. This flaw
Overview
ManageEngine DataSecurity Plus versions prior to 6310 contain an authenticated SQL injection vulnerability in the Reports module. This flaw allows a malicious or compromised technician account to execute arbitrary SQL queries against the underlying database. It matters because successful exploitation could lead to unauthorized data access, modification, or exposure of sensitive enterprise information.
Description
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
Impact
The impact primarily affects confidentiality and integrity, with potential availability impacts depending on database operations. Authenticated users with technician-level privileges are impacted as their credentials can be leveraged to execute unauthorized database queries. This could result in the exfiltration or tampering of sensitive data stored within the application's database.
Remediation
Upgrade ManageEngine DataSecurity Plus to version 6310 or the latest available vendor-supplied patch. Audit existing technician accounts and privileges to ensure the principle of least privilege is enforced. Monitor database activity and application logs for unusual query patterns originating from the Reports module.
Risk context
Rated with a high CVSS v3 score of 7.7, this vulnerability poses a significant risk due to the potential severity of database compromise. However, the requirement for prior authentication limits the attack surface to valid users or compromised credentials. Defenders should prioritize patching based on asset criticality and exposure.
Affected products
- ManageEngine DataSecurity Plus < 6310
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 7.7
- CVSS v4
- —
- EPSS
- —