Zohocorp ManageEngine ADAudit Plus Versions Below 8121 Vulnerable to Authenticated SQL Injection
CVE-2024-5467

8.8HIGH

Key Information:

Vendor
CVE Published:
23 August 2024

Summary

ManageEngine ADAudit Plus versions prior to 8121 expose users to an authenticated SQL injection vulnerability within the account lockout report functionality. This security flaw allows an attacker with valid credentials to execute arbitrary SQL queries through the application, potentially leading to unauthorized access to sensitive information, modification of data, or even complete compromise of affected systems. Organizations using non-updated versions of ADAudit Plus may face significant security risks, making it vital to apply the necessary updates and maintain the integrity of their security posture.

Affected Version(s)

ADAudit Plus 0 < 8121

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.