ZeroHour

CVE-2025-36527

moderate

Authenticated SQL injection in report export in Zoho ManageEngine ADAudit Plus

CVSS 3.1
8.3 high
EPSS
37%p98
Published
()
Modified
AI analysis

ManageEngine ADAudit Plus, Zoho's Active Directory auditing product, contains a SQL injection flaw (CWE-89) in its report export functionality in builds below 8511. An authenticated user with low privileges can trigger it by initiating a report export, where unsanitized input is incorporated into the underlying database query. A successful attacker can read or tamper with data in the product's audit database, with high confidentiality and integrity impact and limited availability impact per the CVSS score, potentially exposing sensitive directory activity records the tool has collected. Any organization running ADAudit Plus builds prior to 8511 is affected; the product's web console typically runs on-premises and is reachable from internal networks or VPN, which constrains attacker reach. No public PoC, CISA KEV listing, or confirmed in-the-wild exploitation is known, although EPSS assigns a 36.5% probability of exploitation within 30 days (98th percentile), suggesting elevated risk.

What to do: Upgrade ADAudit Plus to build 8511 or later, which resolves this SQL injection. Until patched, restrict access to the web console and any externally reachable entry points (reverse proxies, VPN) to trusted accounts, and monitor report-export activity for anomalies. Review export/download logs for signs of abuse by low-privileged accounts.

Affected
Zoho Corp ManageEngine ADAudit Plusall builds below 8511 (fixed in build 8511)
Estimated exposure
moderatelow tens of thousands of on-prem installations worldwide (typically one console per organization) — estimate — ManageEngine markets ADAudit Plus broadly to enterprise IT and it is usually deployed as a single on-premises auditing server per organization, often not internet-exposed; with no public install counts or exposure scans in the data, this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.

Vendors
zohocorp
Products
manageengine adaudit plus
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.