CVE-2024-49574: SQL Injection
Published Nov 18, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
Affected Software
6 affected components
ZohoCorp ManageEngine ADAudit Plus<8.1
ZohoCorp ManageEngine ADAudit Plus=8.1
ZohoCorp ManageEngine ADAudit Plus=8.1-8100
ZohoCorp ManageEngine ADAudit Plus=8.1-8110
ZohoCorp ManageEngine ADAudit Plus=8.1-8120
ZohoCorp ManageEngine ADAudit Plus=8.1-8121
Event History
Nov 18, 2024
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-49574?
CVE-2024-49574 is classified as a high-severity vulnerability due to its potential for SQL Injection exploits.
2
How do I fix CVE-2024-49574?
To fix CVE-2024-49574, upgrade to ManageEngine ADAudit Plus version 8123 or later.
3
What components of Zoho ManageEngine are affected by CVE-2024-49574?
CVE-2024-49574 affects all versions of Zoho ManageEngine ADAudit Plus below 8123.
4
What is the impact of CVE-2024-49574 on the reports module?
The impact of CVE-2024-49574 allows attackers to perform SQL Injection attacks, potentially leading to unauthorized data access.
5
Are older versions of ManageEngine ADAudit Plus still secure after patching for CVE-2024-49574?
No, older versions remain vulnerable even after patching for CVE-2024-49574 and should be upgraded to the latest version.