CVE-2024-5608: SQL Injection
Published Oct 24, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.
Affected Software
5 affected components
ZohoCorp ManageEngine ADAudit Plus<8.1
ZohoCorp ManageEngine ADAudit Plus=8.1
ZohoCorp ManageEngine ADAudit Plus=8.1-8100
ZohoCorp ManageEngine ADAudit Plus=8.1-8110
ZohoCorp ManageEngine ADAudit Plus=8.1-8120
Event History
Oct 24, 2024
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5608?
CVE-2024-5608 is classified as a critical vulnerability due to its potential impact on data integrity through SQL injection.
2
How do I fix CVE-2024-5608?
To fix CVE-2024-5608, upgrade to ManageEngine ADAudit Plus version 8121 or later.
3
What versions of Zoho ManageEngine ADAudit Plus are affected by CVE-2024-5608?
CVE-2024-5608 affects all versions of Zoho ManageEngine ADAudit Plus below 8121.
4
What type of vulnerability is CVE-2024-5608?
CVE-2024-5608 is a SQL Injection vulnerability found in the technician reports feature.
5
What are the potential risks of CVE-2024-5608?
The potential risks of CVE-2024-5608 include unauthorized access to sensitive data and manipulation of the database.