CVE-2024-21775SQL Injection in Exchange Reporter Plus

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGHNVD
CNA8.3
EPSS
0.7%
top 27.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16

Description

Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
SQL Injection2024-02-16
GHSA
GHSA-rq54-4p92-2jhj: Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature2024-02-16
CVE-2024-21775 — SQL Injection | cvebase