First published: Mon May 20 2024(Updated: )
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine | <7271 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49331 is classified as a critical vulnerability due to its ability to allow SQL injection.
To fix CVE-2023-49331, upgrade Zoho ManageEngine ADAudit Plus to version 7271 or later.
CVE-2023-49331 can be exploited to perform SQL injection attacks, potentially allowing unauthorized access to data.
CVE-2023-49331 affects all versions of Zoho ManageEngine ADAudit Plus prior to version 7271.
The vulnerability in CVE-2023-49331 exists in the aggregate reports search option of Zoho ManageEngine ADAudit Plus.