CVE-2021-37422

EUVD-2021-23987
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_adselfservice_plus
𝑥
< 6.1
zohocorpmanageengine_adselfservice_plus
6.1
zohocorpmanageengine_adselfservice_plus
6.1:6100
zohocorpmanageengine_adselfservice_plus
6.1:6101
zohocorpmanageengine_adselfservice_plus
6.1:6102
zohocorpmanageengine_adselfservice_plus
6.1:6103
zohocorpmanageengine_adselfservice_plus
6.1:6104
zohocorpmanageengine_adselfservice_plus
6.1:6105
zohocorpmanageengine_adselfservice_plus
6.1:6106
zohocorpmanageengine_adselfservice_plus
6.1:6107
zohocorpmanageengine_adselfservice_plus
6.1:6108
zohocorpmanageengine_adselfservice_plus
6.1:6109
zohocorpmanageengine_adselfservice_plus
6.1:6110
zohocorpmanageengine_adselfservice_plus
6.1:6111
𝑥
= Vulnerable software versions