First published: Fri Feb 16 2024(Updated: )
Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Exchange Reporter Plus | <5.7 | |
ManageEngine Exchange Reporter Plus | =5.7 | |
ManageEngine Exchange Reporter Plus | =5.7-5700 | |
ManageEngine Exchange Reporter Plus | =5.7-5701 | |
ManageEngine Exchange Reporter Plus | =5.7-5702 | |
ManageEngine Exchange Reporter Plus | =5.7-5703 | |
ManageEngine Exchange Reporter Plus | =5.7-5704 | |
ManageEngine Exchange Reporter Plus | =5.7-5705 | |
ManageEngine Exchange Reporter Plus | =5.7-5706 | |
ManageEngine Exchange Reporter Plus | =5.7-5707 | |
ManageEngine Exchange Reporter Plus | =5.7-5708 | |
ManageEngine Exchange Reporter Plus | =5.7-5709 | |
ManageEngine Exchange Reporter Plus | =5.7-5710 | |
ManageEngine Exchange Reporter Plus | =5.7-5711 | |
ManageEngine Exchange Reporter Plus | =5.7-5712 | |
ManageEngine Exchange Reporter Plus | =5.7-5713 | |
ManageEngine Exchange Reporter Plus | =5.7-5714 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21775 is classified as a high severity vulnerability due to its potential impact on database integrity.
To mitigate CVE-2024-21775, upgrade Zoho ManageEngine Exchange Reporter Plus to version 5.7.5715 or later.
CVE-2024-21775 requires authenticated access to exploit, allowing unintended SQL queries in report exporting.
CVE-2024-21775 affects versions 5.7 and below of Zoho ManageEngine Exchange Reporter Plus.
CVE-2024-21775 is an authenticated SQL injection vulnerability within the report exporting feature.