CVE-2024-5487SQL Injection in Manageengine Adaudit Plus

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGHNVD
CNA8.3
EPSS
1.2%
top 20.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
SQL Injection2024-08-12
GHSA
GHSA-xrf6-53r6-98w9: Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option2024-08-12
CVE-2024-5487 — SQL Injection | cvebase