Loading market data...
← Back to CVE feed

CVE-2026-18912

HIGH CVSS 7.7 View on NVD ↗

Description

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Published: Sep 18, 2026 06:16 UTC Modified: Sep 18, 2026 15:17 UTC