ManageEngine ADSelfService Plus
cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*
- <= 6522
A high-severity authenticated SQL injection vulnerability has been identified in ManageEngine ADSelfService Plus versions 6522 and earlier. This vulnerability allows authenticated technicians to execute arbitrary SQL commands through the Reports module, potentially leading to unauthorized modifications of the ADSelfService Plus database. The issue arises from inadequate validation and sanitization of custom input in SQL queries sent from the Reports module to the database.
Exploitation of this vulnerability could allow authenticated ADSelfService Plus technicians to manipulate the database by executing arbitrary SQL commands, posing a risk of unauthorized data changes.
Users can update to ManageEngine ADSelfService Plus version 6523 or later, using the available service pack.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.