Unauthenticated SQL Injection in Zohocorp ManageEngine Analytics Plus
CVE-2025-8324

9.8CRITICAL

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
11 November 2025

What is CVE-2025-8324?

Zohocorp's ManageEngine Analytics Plus versions 6170 and earlier exhibit a vulnerability that allows attackers to perform unauthenticated SQL injection attacks. This issue arises from an improper filtering configuration, which could lead to unauthorized access to sensitive data stored in the database. Organizations using affected versions should prioritize immediate patching to mitigate potential data breaches and ensure system integrity.

Affected Version(s)

ManageEngine Analytics Plus 0 < 6171

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8324 : Unauthenticated SQL Injection in Zohocorp ManageEngine Analytics Plus