CVE-2024-36518: SQL Injection
Published Aug 12, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.
Affected Software
3 affected components
ZohoCorp ManageEngine ADAudit Plus<8.1
ZohoCorp ManageEngine ADAudit Plus=8.1
ZohoCorp ManageEngine ADAudit Plus=8.1-8100
Event History
Aug 12, 2024
CVE Published
via MITRE·07:13 AM
Data Sourced
via MITRE·07:13 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36518?
CVE-2024-36518 is identified as a critical vulnerability due to the potential for authenticated SQL injection attacks.
2
How do I fix CVE-2024-36518?
To fix CVE-2024-36518, upgrade to Zoho ManageEngine ADAudit Plus version 8110 or higher.
3
What versions of Zoho ManageEngine ADAudit Plus are affected by CVE-2024-36518?
CVE-2024-36518 affects all versions of Zoho ManageEngine ADAudit Plus below 8110.
4
Can CVE-2024-36518 be exploited remotely?
CVE-2024-36518 requires authenticated access to be exploited, meaning it cannot be exploited remotely without valid credentials.
5
What are the implications of CVE-2024-36518 for organizations?
Organizations using vulnerable versions of Zoho ManageEngine ADAudit Plus may face data breaches or unauthorized access to sensitive information due to SQL injection vulnerabilities.