peter bassill · operator
$ cve CVE-2014-8499 JSON

CVE-2014-8499 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 36.4% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS36.37% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2014-11-17
Last modified2026-06-17

Affected (1)

VendorProduct
manageenginepassword manager pro

Public exploits

SourceTitleDate
exploit-dbPassword Manager Pro / Pro MSP - Blind SQL Injection2014-11-10

References

→ the Explorer  ·  watch your stack  ·  NVD