Assigner | ManageEngine |
Reserved | 2024-01-11 |
Published | 2024-05-22 |
Updated | 2024-06-07 |
Description
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 7271
References
https://www.manageengine.com/products/active-directory-audit/sqlfix-7271.html