First published: Mon Mar 17 2025(Updated: )
Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Analytics Plus | <6130 | |
Zoho Analytics | <6130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1724 is considered critical due to the risk of unauthorized account takeover.
To mitigate CVE-2025-1724, upgrade to ManageEngine Analytics Plus or Zoho Analytics version 6130 or later.
CVE-2025-1724 affects on-premise versions of ManageEngine Analytics Plus and Zoho Analytics older than version 6130.
CVE-2025-1724 involves a hardcoded sensitive token that allows for unauthorized access to AD only accounts.
The vendor for CVE-2025-1724 is Zohocorp.