peter bassill · operator
$ cve CVE-2014-8498 JSON

CVE-2014-8498 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 12.7% (pctl 96)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS12.75% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2014-11-17
Last modified2026-06-17

Affected (1)

VendorProduct
zohocorpmanageengine password manager pro

Public exploits

SourceTitleDate
exploit-dbPassword Manager Pro / Pro MSP - Blind SQL Injection2014-11-10

References

→ the Explorer  ·  watch your stack  ·  NVD