ManageEngine ADAudit Plus
cpe:2.3:a:zohocorp:manageengine_adaudit_plus:*:*:*:*:*:*:*
- < 8511
A SQL injection vulnerability has been identified in ManageEngine ADAudit Plus, affecting all versions prior to 8511. This vulnerability arises when exporting reports, allowing authenticated users to execute arbitrary SQL queries and access database entries through the vulnerable export API.
Exploitation of this vulnerability could enable authenticated users to manipulate SQL queries, potentially leading to unauthorized data access or modification within the application's database.
Users are advised to update their ADAudit Plus instances to build 8511 or later. Instructions for downloading the latest build are available on the ManageEngine ADAudit Plus service pack page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.