ManageEngine ADAudit Plus Authenticated SQL Injection Vulnerability in Service Account Auditing Reports

Vulnerability

A SQL injection vulnerability has been identified in ManageEngine ADAudit Plus versions through 8510. This vulnerability allows authenticated users to inject malicious SQL queries into the Service Account Auditing reports, potentially leading to unauthorized access to database information.

Impact

Exploitation of this vulnerability could enable an authenticated user to execute arbitrary SQL queries, allowing access to sensitive database information.

Remediation

Users can upgrade to ManageEngine ADAudit Plus build 8511 to address this vulnerability.

Added: Jun 9, 2025, 11:21 AM
Updated: Jun 9, 2025, 12:24 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.2
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.