PT-2025-21148 · Zohocorp · Zoho Manageengine Adaudit Plus
Published
2025-05-09
·
Updated
2025-06-16
·
CVE-2025-3834
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior
Description:
The issue concerns an authenticated SQL injection in the OU History report. This allows for potential exploitation where an attacker could manipulate database queries.
Recommendations:
For versions 8510 and prior, consider restricting access to the OU History report until a fix is available.
As a temporary workaround, avoid using the OU History report feature in affected versions to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Adaudit Plus