First published: Fri Aug 23 2024(Updated: )
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ADAudit Plus | <8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36517 has been classified as a high-severity vulnerability due to the potential for data manipulation through SQL injection.
To fix CVE-2024-36517, upgrade your ManageEngine ADAudit Plus to version 8000 or newer.
CVE-2024-36517 can enable attackers to execute unauthorized SQL queries, potentially leading to data leakage or compromise.
Any user running ManageEngine ADAudit Plus versions below 8000 is affected by CVE-2024-36517.
Yes, exploitation of CVE-2024-36517 requires authenticated access to the alerts module of ADAudit Plus.