Zohocorp ADAudit Plus Vulnerability: Authenticated SQL Injection in Aggregate Reports' Search Option
CVE-2024-36034
8.8HIGH
Summary
ManageEngine ADAudit Plus, a product from Zohocorp, has a vulnerability that allows for authenticated SQL Injection. This security flaw exists in the search option of aggregate reports within versions prior to 8003. This weakness could potentially be exploited by authenticated users to execute arbitrary SQL commands, leading to unauthorized data exposure or manipulation. Users are urged to upgrade to version 8003 or later to mitigate these risks and secure their systems against possible exploitation.
Affected Version(s)
ADAudit Plus Windows 0 <= 8003
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved