PT-2024-13653 · Zoho · Zoho Manageengine Adaudit Plus

Nhien Pham

+1

·

Published

2024-02-01

·

Updated

2024-12-28

·

CVE-2023-48793

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ADAudit Plus versions through 7250
Description The issue allows SQL Injection in the aggregate report feature. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions through 7250, update to a version later than 7250 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-48793

Affected Products

Zoho Manageengine Adaudit Plus