Authenticated SQL Injection in Zohocorp ManageEngine ADAudit Plus
CVE-2024-5490
8.8HIGH
Summary
Zohocorp's ManageEngine ADAudit Plus, specifically versions prior to 8000, presents a significant security vulnerability due to an authenticated SQL injection flaw in its aggregate reports feature. This vulnerability could permit attackers with authenticated access to execute arbitrary SQL commands, potentially compromising sensitive data within the system. Organizations utilizing these versions should prioritize applying the necessary patches and updates to mitigate the risk of unauthorized data access and maintain the integrity of their data security.
Affected Version(s)
ADAudit Plus 0 < 8000
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved