PT-2024-19049 · Zoho · Zoho Manageengine Exchange Reporter Plus

Minhgalaxy

·

Published

2024-02-16

·

Updated

2024-11-26

·

CVE-2024-21775

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Exchange Reporter Plus versions 5714 and below
Description The issue is related to an Authenticated SQL injection in the report exporting feature.
Recommendations For Zoho ManageEngine Exchange Reporter Plus versions 5714 and below, update to a version above 5714 to resolve the issue. As a temporary workaround, consider restricting access to the report exporting feature until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-21775

Affected Products

Zoho Manageengine Exchange Reporter Plus