CVE-2024-38871SQL Injection in Exchange Reporter Plus

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGHNVD
CNA8.3
EPSS
1.2%
top 20.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26

Description

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
SQL Injection2024-07-26
GHSA
GHSA-xrwv-x9mf-8rh3: Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module2024-07-26
CVE-2024-38871 — SQL Injection | cvebase