First published: Wed May 14 2025(Updated: )
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
ADSelfService Plus | <6513 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3833 has been rated as a critical vulnerability due to its potential for authenticated SQL injection.
To mitigate CVE-2025-3833, upgrade to ManageEngine ADSelfService Plus version 6514 or later.
CVE-2025-3833 affects ManageEngine ADSelfService Plus versions 6513 and earlier.
CVE-2025-3833 is an authenticated SQL injection vulnerability specifically found in MFA reports.
Exploitation of CVE-2025-3833 could allow attackers to execute arbitrary SQL queries, potentially compromising sensitive data.