CVE-2025-3833
largeAuthenticated SQL Injection in ManageEngine ADSelfService Plus MFA Reports
CVE-2025-3833 is an SQL injection flaw (CWE-89) in the MFA reports function of Zoho ManageEngine ADSelfService Plus, affecting builds 6513 and earlier. It is triggered over the network by an authenticated user — any account with access to the self-service portal can reach the vulnerable MFA reports code, with no additional user interaction required. Successful injection gives the attacker high-impact read and write access to the backing database, potentially exposing directory/MFA-related data (e.g., user identity details, MFA contact information) and allowing modification of stored records. All organizations running ADSelfService Plus build 6513 or prior are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the flaw sits in the 99th EPSS percentile with a 44.4% probability of exploitation within 30 days, so defenders should treat it as a near-term risk.
What to do: Upgrade all ADSelfService Plus instances to a fixed build released after 6513 (deploy the latest available build). In the meantime, restrict which accounts can access the MFA reports module and monitor the portal for anomalous report queries or database changes. Because exploitation requires valid portal credentials, prioritize patching for internet-exposed or externally reachable ADSelfService Plus portals and review MFA report data for signs of tampering.
| Zoho Corp (ManageEngine) ManageEngine ADSelfService Plus | 6513 and prior |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
- Vendors
- zohocorp
- Products
- manageengine adselfservice plus
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.