CVE-2024-21775 — SQL Injection in Exchange Reporter Plus
Severity
8.8HIGHNVD
CNA8.3
EPSS
0.7%
top 27.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16
Description
Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9