CVE-2025-9428SQL Injection in Manageengine Analytics Plus

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGHNVD
CNA8.3
EPSS
0.6%
top 30.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21

Description

Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-c9w7-xppr-936q: Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api2025-10-21
CVEList
SQL Injection2025-10-21
CVE-2025-9428 — SQL Injection | cvebase