CVE-2025-3836: SQL Injection
Published May 22, 2025
·Updated
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.
Affected Software
5 affected components
ZohoCorp ManageEngine ADAudit Plus<8510
ZohoCorp ManageEngine ADAudit Plus<8.5
ZohoCorp ManageEngine ADAudit Plus=8.5
ZohoCorp ManageEngine ADAudit Plus=8.5-8500
ZohoCorp ManageEngine ADAudit Plus=8.5-8510
Event History
May 22, 2025
CVE Published
via MITRE·10:38 AM
Data Sourced
via MITRE·10:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3836?
The severity of CVE-2025-3836 is critical due to the potential for authenticated SQL injection.
2
How do I fix CVE-2025-3836?
To fix CVE-2025-3836, upgrade to ManageEngine ADAudit Plus version 8511 or later.
3
Who is affected by CVE-2025-3836?
CVE-2025-3836 affects users of Zohocorp's ManageEngine ADAudit Plus versions 8510 and earlier.
4
What type of vulnerability is CVE-2025-3836?
CVE-2025-3836 is classified as an authenticated SQL injection vulnerability.
5
What version of ManageEngine ADAudit Plus is vulnerable to CVE-2025-3836?
ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to CVE-2025-3836.