CVE-2024-5467: SQL Injection
Published Aug 23, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.
Affected Software
4 affected components
ZohoCorp ManageEngine ADAudit Plus<=8.0
ZohoCorp ManageEngine ADAudit Plus=8.1-8100
ZohoCorp ManageEngine ADAudit Plus=8.1-8110
ZohoCorp ManageEngine ADAudit Plus=8.1-8120
Event History
Aug 23, 2024
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5467?
CVE-2024-5467 has been classified as a high severity vulnerability due to its potential for exploitation via authenticated SQL injection.
2
How do I fix CVE-2024-5467?
To remediate CVE-2024-5467, upgrade your Zoho ManageEngine ADAudit Plus to version 8121 or higher.
3
What versions are affected by CVE-2024-5467?
CVE-2024-5467 affects all versions of Zoho ManageEngine ADAudit Plus below 8121.
4
What type of vulnerability is CVE-2024-5467?
CVE-2024-5467 is an authenticated SQL injection vulnerability.
5
Can CVE-2024-5467 lead to data exposure?
Yes, exploitation of CVE-2024-5467 may allow attackers to manipulate SQL queries, potentially leading to unauthorized access or data exposure.