Zohocorp ADAudit Plus Vulnerability: Authenticated SQL Injection in Aggregate Reports' Search Option
CVE-2024-36034

8.8HIGH

Key Information:

Vendor
CVE Published:
12 August 2024

Summary

ManageEngine ADAudit Plus, a product from Zohocorp, has a vulnerability that allows for authenticated SQL Injection. This security flaw exists in the search option of aggregate reports within versions prior to 8003. This weakness could potentially be exploited by authenticated users to execute arbitrary SQL commands, leading to unauthorized data exposure or manipulation. Users are urged to upgrade to version 8003 or later to mitigate these risks and secure their systems against possible exploitation.

Affected Version(s)

ADAudit Plus Windows 0 <= 8003

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.