ManageEngine ADAudit Plus SQL Injection Vulnerability in Report Exporting API

Vulnerability

A SQL injection vulnerability has been identified in ManageEngine ADAudit Plus, affecting all versions prior to 8511. This vulnerability arises when exporting reports, allowing authenticated users to execute arbitrary SQL queries and access database entries through the vulnerable export API.

Impact

Exploitation of this vulnerability could enable authenticated users to manipulate SQL queries, potentially leading to unauthorized data access or modification within the application's database.

Remediation

Users are advised to update their ADAudit Plus instances to build 8511 or later. Instructions for downloading the latest build are available on the ManageEngine ADAudit Plus service pack page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.