← Back to CVE List
CVE-2017-16543
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt