CVE-2024-5556: SQL Injection
Published Aug 23, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.
Affected Software
1 affected component
ZohoCorp ManageEngine ADAudit Plus<8.0
Event History
Aug 23, 2024
CVE Published
via MITRE·01:52 PM
Data Sourced
via MITRE·01:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5556?
CVE-2024-5556 has a high severity rating due to its potential impact on authenticated SQL injection vulnerabilities.
2
How do I fix CVE-2024-5556?
To fix CVE-2024-5556, upgrade your Zoho ManageEngine ADAudit Plus to version 8000 or later.
3
What impact does CVE-2024-5556 have on affected systems?
CVE-2024-5556 can allow attackers to execute arbitrary SQL commands, leading to unauthorized data access or modification.
4
Which versions are affected by CVE-2024-5556?
CVE-2024-5556 affects all versions of Zoho ManageEngine ADAudit Plus below 8000.
5
Is CVE-2024-5556 an authenticated or unauthenticated vulnerability?
CVE-2024-5556 is an authenticated SQL injection vulnerability, requiring user authentication for exploitation.