Home

Description

Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.

PUBLISHED Reserved 2025-07-30 | Published 2025-11-11 | Updated 2025-11-13 | Assigner Zohocorp




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

Any version before 6171
affected

References

www.manageengine.com/analytics-plus/CVE-2025-8324.html

cve.org (CVE-2025-8324)

nvd.nist.gov (CVE-2025-8324)

Download JSON