Description
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 7271
References
www.manageengine.com/...ive-directory-audit/sqlfix-7271.html
www.manageengine.com/...ive-directory-audit/sqlfix-7271.html