Executive brief
ManageEngine DataSecurity Plus is a file server auditing and data security solution used to monitor and protect sensitive files and ensure compliance. An authenticated technician can exploit a SQL injection flaw in the Reports module to execute arbitrary SQL queries, potentially exposing or corrupting sensitive audit data and compliance records stored in the system.
Technical details
This is an authenticated SQL injection vulnerability in the Reports module of DataSecurity Plus versions 6300 and earlier. The vulnerability exists in the filter processing logic where user-supplied input is not properly sanitized before SQL query construction. An authenticated technician with access to the Reports feature can inject arbitrary SQL commands through filter parameters to execute unauthorized database queries. The attack requires valid authentication credentials. ManageEngine has patched this vulnerability in version 6310 (released August 6, 2026) by strengthening input sanitization and expanding SQL escaping coverage across all filter types.
Affected products
- ManageEngine DataSecurity Plus 6300 and earlier
Timeline
- 2026-08-06: patched: Fix released in version 6310
- 2026-09-18: disclosed