First published: Fri Aug 23 2024(Updated: )
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ADAudit Plus | <8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36515 is classified with a medium severity due to its potential for SQL injection attacks.
To fix CVE-2024-36515, upgrade your ManageEngine ADAudit Plus to version 8000 or later.
CVE-2024-36515 affects all versions of ManageEngine ADAudit Plus below version 8000.
Yes, CVE-2024-36515 is an authenticated SQL injection vulnerability in the dashboard.
CVE-2024-36515 and CVE-2024-36516 are different vulnerabilities affecting the ADAudit Plus dashboard, each with its own specific exploit details.