Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Minh Vo Van

Researcher fromGalaxyOne
#15256of 53,635
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2024-26855
8.8
2024-08-12
Zohocorp · Zoho Manageengine Adaudit Plus · CVE-2024-36034
**Name of the Vulnerable Software and Affected Versions** Zohocorp ManageEngine ADAudit Plus versions below 8003 **Description** The issue concerns an authenticated SQL Injection vulnerability in the aggregate reports' search option. This allows attackers to inject malicious SQL code, potentially leading to unauthorized access or data manipulation. **Recommendations** For Zohocorp ManageEngine ADAudit Plus versions below 8003, update to a version 8003 or later to resolve the issue. As a temporary workaround, consider restricting access to the aggregate reports' search option until a patch is applied.
PT-2024-26856
8.8
2024-08-12
Zohocorp · Zoho Manageengine Adaudit Plus · CVE-2024-36035
**Name of the Vulnerable Software and Affected Versions** Zohocorp ManageEngine ADAudit Plus versions below 8003 **Description** The issue is related to an authenticated SQL Injection vulnerability in user session recording. **Recommendations** For Zohocorp ManageEngine ADAudit Plus versions below 8003, update to a version 8003 or later to resolve the issue.