Zohocorp ADAudit Plus Vulnerability: Authenticated SQL Injection in Aggregate Reports' Search Option
CVE-2024-36034
8.8HIGH
What is CVE-2024-36034?
ManageEngine ADAudit Plus, a product from Zohocorp, has a vulnerability that allows for authenticated SQL Injection. This security flaw exists in the search option of aggregate reports within versions prior to 8003. This weakness could potentially be exploited by authenticated users to execute arbitrary SQL commands, leading to unauthorized data exposure or manipulation. Users are urged to upgrade to version 8003 or later to mitigate these risks and secure their systems against possible exploitation.
Affected Version(s)
ADAudit Plus Windows 0 <= 8003