CVE-2024-5527
Zohocorp
CVE-2024-5527: ManageEngine ADAudit Plus is vulnerable to SQL Injection attacks. This security flaw allows authenticated attackers to inject malicious SQL code into file auditing configurations of ADAudit Plus versions below 8110. While the CVSS score is 8.8, SOCRadar's SVRS of 77 indicates a significant risk requiring prompt attention, though it does not reach the threshold of a critical vulnerability. Successful exploitation of this vulnerability could lead to data breaches, unauthorized access, or modification of sensitive information within the database. Organizations using affected versions of ManageEngine ADAudit Plus should immediately apply the necessary patches or upgrades. The ability to manipulate file auditing configurations makes this a serious security concern.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.