ManageEngine ADAudit Plus Authenticated SQL Injection Vulnerability in Alerts Module

Vulnerability

A high-severity authenticated SQL injection vulnerability has been identified in the alerts module of ManageEngine ADAudit Plus, affecting all versions prior to 8511. This vulnerability allows authenticated users to execute arbitrary SQL queries, potentially leading to unauthorized access to database information.

Impact

Exploitation of this vulnerability could enable an authenticated user to manipulate SQL queries and access sensitive data from the database.

Remediation

Users are advised to update their ADAudit Plus instance to the latest build, 8511, using the available service pack.

Added: Jun 9, 2025, 12:19 PM
Updated: Jun 9, 2025, 12:19 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.2
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.