Security Advisory
CVE-2019-19649
9.8
CRITICAL
Vulnerability Description
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
Published Date
December 11, 2019
Official Source
NIST NVD Advisory