PT-2025-21148 · Zohocorp · Zoho Manageengine Adaudit Plus

Published

2025-05-09

·

Updated

2025-06-16

·

CVE-2025-3834

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Zohocorp ManageEngine ADAudit Plus versions 8510 and prior
Description: The issue concerns an authenticated SQL injection in the OU History report. This allows for potential exploitation where an attacker could manipulate database queries.
Recommendations: For versions 8510 and prior, consider restricting access to the OU History report until a fix is available. As a temporary workaround, avoid using the OU History report feature in affected versions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2026-00235
CVE-2025-3834

Affected Products

Zoho Manageengine Adaudit Plus