Zohocorp ManageEngine ADSelfService Plus
cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*
- <= 6513
A high-severity authenticated SQL injection vulnerability has been identified in ManageEngine ADSelfService Plus versions through 6513. This vulnerability allows technicians to manipulate SQL queries related to MFA reports, potentially leading to unauthorized changes in the application’s database.
Exploitation of this vulnerability could allow authenticated ADSelfService Plus technicians to execute arbitrary SQL commands, with the potential to modify the ADSelfService Plus database without authorization.
Users can update to ManageEngine ADSelfService Plus version 6514 or later. Instructions for downloading the latest version are available on the ManageEngine website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.