CVE-2024-5527: SQL Injection
Published Aug 12, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.
Affected Software
3 affected components
ZohoCorp ManageEngine ADAudit Plus<8.1
ZohoCorp ManageEngine ADAudit Plus=8.1
ZohoCorp ManageEngine ADAudit Plus=8.1-8100
Event History
Aug 12, 2024
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5527?
CVE-2024-5527 holds a critical severity rating due to the potential for authenticated SQL Injection.
2
How do I fix CVE-2024-5527?
To fix CVE-2024-5527, upgrade Zoho ManageEngine ADAudit Plus to version 8110 or above.
3
Which versions of Zoho ManageEngine ADAudit Plus are affected by CVE-2024-5527?
CVE-2024-5527 affects all versions of Zoho ManageEngine ADAudit Plus below 8110.
4
What type of vulnerability is CVE-2024-5527?
CVE-2024-5527 is an authenticated SQL Injection vulnerability.
5
Are there any known exploits for CVE-2024-5527?
At this time, there are no specific public exploits reported for CVE-2024-5527, but it is advisable to secure your systems.