# Security Updates - CVE Details | ManageEngine Applications Manager ## CVE-2017-16849 ### SQL injection via the forpage parameter. ## Vulnerability Details | Field | Details | |---|---| | Impact | **CVSS V3 rating:** 9.8 CRITICAL | | Reported | 16 November 2017 | | Fixed | 11 December 2017 | | Affected Builds | Till Build 13520 | | Fixed in | Build 13530 | | Overview | SQL injection via the forpage parameter. | | Recommended Fix | **Upgrade to Applications Manager Version 13530 or above.** | ## Description ManageEngine Applications Manager allowed SQL injection via the forpage parameter while displaying dashboards. We recommend that you upgrade to Applications Manager Version 13530 and above to fix this issue. ## Source and Acknowledgements Find out more about CVE-2017-16849 from the [CVE dictionary](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16849) and [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-16849). Other Resources: [https://code610.blogspot.com/2017/11/more-sql-injections-in-manageengine.html](https://code610.blogspot.com/2017/11/more-sql-injections-in-manageengine.html) ## Need Help? For clarification or corrections please contact our [support team](https://www.manageengine.com/products/applications_manager/support.html) or email us at [appmanager-support@manageengine.com](mailto:appmanager-support@manageengine.com)