CVE-2025-1724: Account Takeover
Published Mar 17, 2025
·Updated
Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.
Affected Software
2 affected components
ZohoCorp ManageEngine Analytics Plus<6130
ZohoCorp Zoho Analytics<6130
Event History
Mar 17, 2025
CVE Published
via MITRE·06:57 AM
Data Sourced
via MITRE·06:57 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1724?
CVE-2025-1724 is considered critical due to the risk of unauthorized account takeover.
2
How do I fix CVE-2025-1724?
To mitigate CVE-2025-1724, upgrade to ManageEngine Analytics Plus or Zoho Analytics version 6130 or later.
3
What systems are affected by CVE-2025-1724?
CVE-2025-1724 affects on-premise versions of ManageEngine Analytics Plus and Zoho Analytics older than version 6130.
4
What is the nature of the vulnerability in CVE-2025-1724?
CVE-2025-1724 involves a hardcoded sensitive token that allows for unauthorized access to AD only accounts.
5
Who is the vendor for CVE-2025-1724?
The vendor for CVE-2025-1724 is Zohocorp.