CVE-2025-41403: SQL Injection
Published May 22, 2025
·Updated
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.
Affected Software
5 affected components
ZohoCorp ManageEngine ADAudit Plus<8510
ZohoCorp ManageEngine ADAudit Plus<8.5
ZohoCorp ManageEngine ADAudit Plus=8.5
ZohoCorp ManageEngine ADAudit Plus=8.5-8500
ZohoCorp ManageEngine ADAudit Plus=8.5-8510
Event History
May 22, 2025
CVE Published
via MITRE·10:39 AM
Data Sourced
via MITRE·10:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41403?
CVE-2025-41403 is classified as a critical severity vulnerability due to its potential impact on data integrity and confidentiality.
2
How do I fix CVE-2025-41403?
To mitigate CVE-2025-41403, upgrade to the latest version of Zohocorp ManageEngine ADAudit Plus that addresses this vulnerability.
3
What type of vulnerability is CVE-2025-41403?
CVE-2025-41403 is an authenticated SQL injection vulnerability affecting specific versions of ManageEngine ADAudit Plus.
4
Who is affected by CVE-2025-41403?
Users of Zohocorp ManageEngine ADAudit Plus versions 8510 and earlier are affected by CVE-2025-41403.
5
What does CVE-2025-41403 exploit?
CVE-2025-41403 exploits vulnerabilities in the application’s handling of service account audit data.