First published: Mon May 20 2024(Updated: )
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine | <7271 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49335 is considered a critical vulnerability due to its potential for SQL injection, which can lead to unauthorized data access.
To fix CVE-2023-49335, update Zoho ManageEngine ADAudit Plus to version 7271 or later.
CVE-2023-49335 affects all versions of Zoho ManageEngine ADAudit Plus below version 7271.
CVE-2023-49335 is a SQL injection vulnerability that allows attackers to manipulate database queries.
Exploitation of CVE-2023-49335 could allow an attacker to execute arbitrary SQL queries, potentially leading to data exposure or manipulation.