CVE-2024-36034: SQL Injection
Published Aug 12, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.
Affected Software
4 affected components
ZohoCorp ManageEngine ADAudit Plus<8.0
ZohoCorp ManageEngine ADAudit Plus=8.0-8000
ZohoCorp ManageEngine ADAudit Plus=8.0-8001
ZohoCorp ManageEngine ADAudit Plus=8.0-8002
Event History
Aug 12, 2024
CVE Published
via MITRE·07:23 AM
Data Sourced
via MITRE·07:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36034?
CVE-2024-36034 has been classified as a critical vulnerability due to its SQL Injection risk.
2
How do I fix CVE-2024-36034?
To fix CVE-2024-36034, upgrade Zoho ManageEngine ADAudit Plus to version 8003 or later.
3
What systems are affected by CVE-2024-36034?
CVE-2024-36034 affects Zoho ManageEngine ADAudit Plus versions below 8003.
4
What kind of vulnerability is CVE-2024-36034?
CVE-2024-36034 is an authenticated SQL Injection vulnerability found in the aggregate reports' search option.
5
Can CVE-2024-36034 be exploited remotely?
Yes, CVE-2024-36034 can potentially be exploited by authenticated users remotely.