PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by INSERT/**/INTO.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Manageengine_opmanager | Zohocorp | * | 11.5 (including) |
| Manageengine_opmanager | Zohocorp | 11.6 (including) | 11.6 (including) |