Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_analytics_plus | - | 6.1 |
| zohocorp / manageengine_analytics_plus | 6.1-6100 | 6.1-6100.x |
| zohocorp / manageengine_analytics_plus | 6.1-6110 | 6.1-6110.x |
| zohocorp / manageengine_analytics_plus | 6.1-6120 | 6.1-6120.x |
| zohocorp / manageengine_analytics_plus | 6.1-6130 | 6.1-6130.x |
| zohocorp / manageengine_analytics_plus | 6.1-6140 | 6.1-6140.x |
| zohocorp / manageengine_analytics_plus | 6.1-6150 | 6.1-6150.x |
| zohocorp / manageengine_analytics_plus | 6.1-6160 | 6.1-6160.x |
| zohocorp / manageengine_analytics_plus | 6.1-6170 | 6.1-6170.x |
| zohocorp / manageengine_analytics_plus | 6.1-6171 | 6.1-6171.x |