CVE-2025-8324 PUBLISHED

SQL Injection

Assigner: Zohocorp
Reserved: 30.07.2025 Published: 11.11.2025 Updated: 13.11.2025

Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Zohocorp
Product ManageEngine Analytics Plus
Versions Default: unaffected
  • affected from 0 to 6171 (excl.)

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE