CVE-2025-41407

EUVD-2025-27988
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_adaudit_plus
𝑥
< 8.5
zohocorpmanageengine_adaudit_plus
8.5
zohocorpmanageengine_adaudit_plus
8.5:8500
zohocorpmanageengine_adaudit_plus
8.5:8510
𝑥
= Vulnerable software versions