SQL Injection Vulnerability in Zoho ManageEngine ADSelfService Plus
CVE-2021-37422
9.8CRITICAL
What is CVE-2021-37422?
Zoho ManageEngine ADSelfService Plus versions 6111 and earlier are exposed to an SQL Injection vulnerability. This security flaw arises during the database linking process, which could allow an attacker to execute arbitrary SQL queries, potentially compromising sensitive data and the overall integrity of the server's database. Organizations using affected versions are strongly advised to apply the latest security patches and monitor their systems for any suspicious activities.
References
EPSS Score
26% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved