SQL injection in Zoho ManageEngine ADAudit Plus - #VU98748

 

SQL injection in Zoho ManageEngine ADAudit Plus - #VU98748

Published: October 16, 2024


Vulnerability identifier: #VU98748
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data within the Session Recording and the Search function in Aggregate Reports. A remote user can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.


Affected software

Zoho ManageEngine ADAudit Plus

Remediation

Install updates from vendor's website.

Zoho ManageEngine ADAudit Plus - update to 8003

External References

Related Security Bulletins