CVE-2025-36527
moderateAuthenticated SQL injection in report export in Zoho ManageEngine ADAudit Plus
ManageEngine ADAudit Plus, Zoho's Active Directory auditing product, contains a SQL injection flaw (CWE-89) in its report export functionality in builds below 8511. An authenticated user with low privileges can trigger it by initiating a report export, where unsanitized input is incorporated into the underlying database query. A successful attacker can read or tamper with data in the product's audit database, with high confidentiality and integrity impact and limited availability impact per the CVSS score, potentially exposing sensitive directory activity records the tool has collected. Any organization running ADAudit Plus builds prior to 8511 is affected; the product's web console typically runs on-premises and is reachable from internal networks or VPN, which constrains attacker reach. No public PoC, CISA KEV listing, or confirmed in-the-wild exploitation is known, although EPSS assigns a 36.5% probability of exploitation within 30 days (98th percentile), suggesting elevated risk.
What to do: Upgrade ADAudit Plus to build 8511 or later, which resolves this SQL injection. Until patched, restrict access to the web console and any externally reachable entry points (reverse proxies, VPN) to trusted accounts, and monitor report-export activity for anomalies. Review export/download logs for signs of abuse by low-privileged accounts.
| Zoho Corp ManageEngine ADAudit Plus | all builds below 8511 (fixed in build 8511) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
- Vendors
- zohocorp
- Products
- manageengine adaudit plus
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.