CVE-2025-3834: SQL Injection
Published May 14, 2025
·Updated
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.
Affected Software
5 affected components
ZohoCorp ManageEngine ADAudit Plus<8510
ZohoCorp ManageEngine ADAudit Plus<8.5
ZohoCorp ManageEngine ADAudit Plus=8.5
ZohoCorp ManageEngine ADAudit Plus=8.5-8500
ZohoCorp ManageEngine ADAudit Plus=8.5-8510
Event History
May 14, 2025
CVE Published
via MITRE·11:05 AM
Data Sourced
via MITRE·11:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3834?
CVE-2025-3834 has been assigned a severity rating that indicates a critical risk due to the potential for unauthorized access via SQL injection.
2
How do I fix CVE-2025-3834?
To fix CVE-2025-3834, upgrade to a version of Zohocorp ManageEngine ADAudit Plus that is newer than 8510.
3
What type of vulnerability is CVE-2025-3834?
CVE-2025-3834 is classified as an authenticated SQL injection vulnerability.
4
What versions of Zohocorp ManageEngine ADAudit Plus are affected by CVE-2025-3834?
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are affected by CVE-2025-3834.
5
Can CVE-2025-3834 be exploited remotely?
CVE-2025-3834 requires authenticated access to be exploited, thus not fully remote, but it poses significant risks if credentials are compromised.