ManageEngine ADAudit Plus
cpe:2.3:a:zohocorp:manageengine_adaudit_plus:*:*:*:*:*:*:*
- < 8511
A high-severity authenticated SQL injection vulnerability has been identified in the alerts module of ManageEngine ADAudit Plus, affecting all versions prior to 8511. This vulnerability allows authenticated users to execute arbitrary SQL queries, potentially leading to unauthorized access to database information.
Exploitation of this vulnerability could enable an authenticated user to manipulate SQL queries and access sensitive data from the database.
Users are advised to update their ADAudit Plus instance to the latest build, 8511, using the available service pack.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.