CVE-2025-41407: SQL Injection
Published May 23, 2025
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
Affected Software
5 affected components
ZohoCorp ManageEngine ADAudit Plus<8511
ZohoCorp ManageEngine ADAudit Plus<8.5
ZohoCorp ManageEngine ADAudit Plus=8.5
ZohoCorp ManageEngine ADAudit Plus=8.5-8500
ZohoCorp ManageEngine ADAudit Plus=8.5-8510
Event History
May 23, 2025
CVE Published
via MITRE·10:29 AM
Data Sourced
via MITRE·10:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41407?
CVE-2025-41407 is classified as a high severity vulnerability due to its potential for SQL injection exploitation.
2
How do I fix CVE-2025-41407?
To mitigate CVE-2025-41407, upgrade Zohocorp ManageEngine ADAudit Plus to version 8511 or later.
3
What is the impact of CVE-2025-41407?
CVE-2025-41407 could allow an attacker to execute arbitrary SQL queries, compromising database security and integrity.
4
Which versions of ManageEngine ADAudit Plus are affected by CVE-2025-41407?
All versions of Zohocorp ManageEngine ADAudit Plus below version 8511 are affected by CVE-2025-41407.
5
Is there a workaround for CVE-2025-41407?
There is no formal workaround for CVE-2025-41407; the recommended action is to apply the security update.