CVE-2024-38871 — SQL Injection in Exchange Reporter Plus
Severity
8.8HIGHNVD
CNA8.3
EPSS
1.2%
top 20.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Description
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9