PT-2024-33553 · Zohocorp · Zoho Manageengine Adaudit Plus

Published

2024-11-18

·

Updated

2024-11-20

·

CVE-2024-49574

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zohocorp ManageEngine ADAudit Plus versions below 8123
Description The issue is related to SQL Injection in the reports module. This can potentially lead to data compromise, including access to sensitive information or manipulation and destruction of critical data.
Recommendations For versions below 8123, upgrade to a version above 8123 to resolve the issue. As a temporary workaround, consider restricting access to the reports module until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-49574

Affected Products

Zoho Manageengine Adaudit Plus