CVE-2025-3833

Zohocorp ManageEngineADSelfService Plus versions6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
ZohocorpCNA
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
VendorProductVersion
zohocorpmanageengine_adselfservice_plus
𝑥
< 6.5
zohocorpmanageengine_adselfservice_plus
6.5:6500
zohocorpmanageengine_adselfservice_plus
6.5:6501
zohocorpmanageengine_adselfservice_plus
6.5:6502
zohocorpmanageengine_adselfservice_plus
6.5:6503
zohocorpmanageengine_adselfservice_plus
6.5:6504
zohocorpmanageengine_adselfservice_plus
6.5:6505
zohocorpmanageengine_adselfservice_plus
6.5:6506
zohocorpmanageengine_adselfservice_plus
6.5:6507
zohocorpmanageengine_adselfservice_plus
6.5:6508
zohocorpmanageengine_adselfservice_plus
6.5:6509
zohocorpmanageengine_adselfservice_plus
6.5:6510
zohocorpmanageengine_adselfservice_plus
6.5:6511
zohocorpmanageengine_adselfservice_plus
6.5:6512
zohocorpmanageengine_adselfservice_plus
6.5:6513
𝑥
= Vulnerable software versions