CVE-2023-48792

EUVD-2023-52825
Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_adaudit_plus
𝑥
< 7.2
zohocorpmanageengine_adaudit_plus
7.2:7200
zohocorpmanageengine_adaudit_plus
7.2:7201
zohocorpmanageengine_adaudit_plus
7.2:7202
zohocorpmanageengine_adaudit_plus
7.2:7203
zohocorpmanageengine_adaudit_plus
7.2:7210
zohocorpmanageengine_adaudit_plus
7.2:7211
zohocorpmanageengine_adaudit_plus
7.2:7212
zohocorpmanageengine_adaudit_plus
7.2:7213
zohocorpmanageengine_adaudit_plus
7.2:7215
zohocorpmanageengine_adaudit_plus
7.2:7220
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
manageengineadaudit_plus
𝑥
< build_7271
ADP