CVE-2025-8324: SQL Injection
Published Nov 11, 2025
·Updated
Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.
Affected Software
1 affected component
Zohocorp ManageEngine Analytics Plus<=6170
Event History
Nov 11, 2025
CVE Published
via MITRE·01:04 PM
Data Sourced
via MITRE·01:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-8324?
CVE-2025-8324 is classified as a critical vulnerability due to its potential for unauthorized access via SQL injection.
2
How do I fix CVE-2025-8324?
To fix CVE-2025-8324, upgrade to ManageEngine Analytics Plus version 6171 or later, which addresses the vulnerability.
3
What are the consequences of exploiting CVE-2025-8324?
Exploiting CVE-2025-8324 allows an attacker to perform unauthorized SQL queries, potentially compromising sensitive data.
4
Which versions of ManageEngine Analytics Plus are affected by CVE-2025-8324?
ManageEngine Analytics Plus versions 6170 and below are affected by CVE-2025-8324.
5
Is authentication required to exploit CVE-2025-8324?
No, CVE-2025-8324 can be exploited without authentication, making it particularly dangerous.