PT-2024-39647 · Zoho · Zoho Manageengine Exchange Reporter Plus

Published

2024-11-04

·

Updated

2024-11-06

·

CVE-2024-9459

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior
Description The issue concerns an authenticated SQL Injection in the reports module.
Recommendations For versions 5718 and prior, update to a version later than 5718 to resolve the issue. As a temporary workaround, consider restricting access to the reports module until a patch is available. Avoid using the reports module in Zohocorp ManageEngine Exchange Reporter Plus until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-9459

Affected Products

Zoho Manageengine Exchange Reporter Plus