First published: Mon Aug 12 2024(Updated: )
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ADAudit Plus | <8.1 | |
Zoho ManageEngine ADAudit Plus | =8.1 | |
Zoho ManageEngine ADAudit Plus | =8.1-8100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36518 is identified as a critical vulnerability due to the potential for authenticated SQL injection attacks.
To fix CVE-2024-36518, upgrade to Zoho ManageEngine ADAudit Plus version 8110 or higher.
CVE-2024-36518 affects all versions of Zoho ManageEngine ADAudit Plus below 8110.
CVE-2024-36518 requires authenticated access to be exploited, meaning it cannot be exploited remotely without valid credentials.
Organizations using vulnerable versions of Zoho ManageEngine ADAudit Plus may face data breaches or unauthorized access to sensitive information due to SQL injection vulnerabilities.