First published: Mon Aug 12 2024(Updated: )
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ADAudit Plus | <8.1 | |
Zoho ManageEngine ADAudit Plus | =8.1 | |
Zoho ManageEngine ADAudit Plus | =8.1-8100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5487 has been classified as a high severity vulnerability due to the potential for unauthorized data access through SQL injection.
To remediate CVE-2024-5487, upgrade to Zoho ManageEngine ADAudit Plus version 8110 or later.
CVE-2024-5487 affects all versions of Zoho ManageEngine ADAudit Plus below version 8110.
CVE-2024-5487 allows authenticated SQL Injection attacks through the attack surface analyzer's export option.
There are no officially recommended workarounds for CVE-2024-5487; upgrading the software is the advised action.