CVE-2025-9428

EUVD-2025-35160
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
ZohocorpCNA
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_analytics_plus
𝑥
< 6.1
zohocorpmanageengine_analytics_plus
6.1:6100
zohocorpmanageengine_analytics_plus
6.1:6110
zohocorpmanageengine_analytics_plus
6.1:6120
zohocorpmanageengine_analytics_plus
6.1:6130
zohocorpmanageengine_analytics_plus
6.1:6140
zohocorpmanageengine_analytics_plus
6.1:6150
zohocorpmanageengine_analytics_plus
6.1:6160
zohocorpmanageengine_analytics_plus
6.1:6170
zohocorpmanageengine_analytics_plus
6.1:6171
𝑥
= Vulnerable software versions