rootpwn

high · CVSS v3 7.7

CVE-2026-18912

ManageEngine DataSecurity Plus versions prior to 6310 contain an authenticated SQL injection vulnerability in the Reports module. This flaw

Overview

ManageEngine DataSecurity Plus versions prior to 6310 contain an authenticated SQL injection vulnerability in the Reports module. This flaw allows a malicious or compromised technician account to execute arbitrary SQL queries against the underlying database. It matters because successful exploitation could lead to unauthorized data access, modification, or exposure of sensitive enterprise information.

Description

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

Impact

The impact primarily affects confidentiality and integrity, with potential availability impacts depending on database operations. Authenticated users with technician-level privileges are impacted as their credentials can be leveraged to execute unauthorized database queries. This could result in the exfiltration or tampering of sensitive data stored within the application's database.

Remediation

Upgrade ManageEngine DataSecurity Plus to version 6310 or the latest available vendor-supplied patch. Audit existing technician accounts and privileges to ensure the principle of least privilege is enforced. Monitor database activity and application logs for unusual query patterns originating from the Reports module.

Risk context

Rated with a high CVSS v3 score of 7.7, this vulnerability poses a significant risk due to the potential severity of database compromise. However, the requirement for prior authentication limits the attack surface to valid users or compromised credentials. Defenders should prioritize patching based on asset criticality and exposure.

Affected products

  • ManageEngine DataSecurity Plus < 6310

Scores

Severity
high
CVSS v2
6.8
CVSS v3
7.7
CVSS v4
EPSS

SQLi ManageEngine DataSecurity Plus Authenticated Reports Module High Severity Database Security

← All CVEs