Home
MEDIUM: 4.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LDefault status
unaffected
Any version before 7271
affected
Description
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 7271
References
www.manageengine.com/...ive-directory-audit/sqlfix-7271.html
www.manageengine.com/...ive-directory-audit/sqlfix-7271.html