Security experts at Digital Defense have discovered several vulnerabilities in the products of the Zoho-owned ManageEngine. The flaws affect ServiceDesk Plus, Service Plus MSP, OpManager, Firewall Analyzer, Network Configuration Manager, OpUtils and NetFlow Analyzer. The company promptly released security updates to address the vulnerabilities discovered by researchers. The vulnerabilities include unauthenticated file upload, blind SQL injection, authenticated remote code execution and user enumeration, potentially revealing sensitive information or full compromise of the application.”]
Source: http://securityaffairs.co/wordpress/68545/breaking-news/manageengine-flaws.html

