Zohocorp ManageEngine ADAudit Plus vulnerable to SQL Injection
CVE-2024-5487
8.8HIGH
Summary
ManageEngine ADAudit Plus by Zohocorp contains a significant vulnerability identified as an authenticated SQL Injection, specifically affecting versions below 8110. This vulnerability arises in the attack surface analyzer's export option, allowing an attacker with valid credentials to manipulate SQL queries, potentially leading to unauthorized data access or data compromise. Organizations using these affected versions should implement remediation measures to safeguard against exploitation and ensure the integrity and confidentiality of their data.
Affected Version(s)
ADAudit Plus Windows 0 <= 8110
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved