First published: Wed May 22 2024(Updated: )
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine | <7271 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21791 is considered a high-severity vulnerability due to potential SQL injection risks.
To fix CVE-2024-21791, upgrade to Zoho ManageEngine ADAudit Plus version 7271 or later.
CVE-2024-21791 allows for SQL injection attacks that can compromise the integrity of lockout history data.
CVE-2024-21791 affects users of Zoho ManageEngine ADAudit Plus versions below 7271, but non-admin users cannot exploit the vulnerability.
While CVE-2024-21791 has high severity, exploitation requires specific conditions related to user permissions.