# Security Updates - CVE Details | ManageEngine Applications Manager ## CVE-2018-15168 ### SQL Injection vulnerability using the resids parameter. ## Vulnerability Details | | | |---|---| | Impact | **CVSS V3 rating:** | | Reported | 18 July 2018 | | Fixed | 25 July 2018 | | Affected Builds | Till Build 13810 | | Fixed in | Build 13820 | | Overview | SQL Injection vulnerability using the resids parameter in the Edit Display Name page | | **Recommended Fix** | **Upgrade to Applications Manager Version 13820 or above.** | ### Description A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager via the resids parameter in a `/editDisplaynames.do?method=editDisplaynames` GET request. We recommend that you upgrade to Applications Manager Version 13820 and above to fix this issue. ### Source and Acknowledgements Find out more about CVE-2018-15168 from the [CVE dictionary](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15168) and [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-15168). Other Resources: [https://github.com/x-f1v3/ForCve/issues/2](https://github.com/x-f1v3/ForCve/issues/2) ### Need Help? For clarification or corrections please contact our [support team](https://www.manageengine.com/products/applications_manager/support.html) or email us at [appmanager-support@manageengine.com](mailto:appmanager-support@manageengine.com)