First published: Mon Nov 18 2024(Updated: )
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ADAudit Plus | <8.1 | |
Zoho ManageEngine ADAudit Plus | =8.1 | |
Zoho ManageEngine ADAudit Plus | =8.1-8100 | |
Zoho ManageEngine ADAudit Plus | =8.1-8110 | |
Zoho ManageEngine ADAudit Plus | =8.1-8120 | |
Zoho ManageEngine ADAudit Plus | =8.1-8121 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49574 is classified as a high-severity vulnerability due to its potential for SQL Injection exploits.
To fix CVE-2024-49574, upgrade to ManageEngine ADAudit Plus version 8123 or later.
CVE-2024-49574 affects all versions of Zoho ManageEngine ADAudit Plus below 8123.
The impact of CVE-2024-49574 allows attackers to perform SQL Injection attacks, potentially leading to unauthorized data access.
No, older versions remain vulnerable even after patching for CVE-2024-49574 and should be upgraded to the latest version.