ZeroHour

CVE-2025-3833

large

Authenticated SQL Injection in ManageEngine ADSelfService Plus MFA Reports

CVSS 3.1
8.1 high
EPSS
44%p99
Published
()
Modified
AI analysis

CVE-2025-3833 is an SQL injection flaw (CWE-89) in the MFA reports function of Zoho ManageEngine ADSelfService Plus, affecting builds 6513 and earlier. It is triggered over the network by an authenticated user — any account with access to the self-service portal can reach the vulnerable MFA reports code, with no additional user interaction required. Successful injection gives the attacker high-impact read and write access to the backing database, potentially exposing directory/MFA-related data (e.g., user identity details, MFA contact information) and allowing modification of stored records. All organizations running ADSelfService Plus build 6513 or prior are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the flaw sits in the 99th EPSS percentile with a 44.4% probability of exploitation within 30 days, so defenders should treat it as a near-term risk.

What to do: Upgrade all ADSelfService Plus instances to a fixed build released after 6513 (deploy the latest available build). In the meantime, restrict which accounts can access the MFA reports module and monitor the portal for anomalous report queries or database changes. Because exploitation requires valid portal credentials, prioritize patching for internet-exposed or externally reachable ADSelfService Plus portals and review MFA report data for signs of tampering.

Affected
Zoho Corp (ManageEngine) ManageEngine ADSelfService Plus6513 and prior
Estimated exposure
largetens of thousands of enterprise deployments, covering likely hundreds of thousands to low millions of AD end users — ADSelfService Plus is a long-established, widely adopted on-premises AD self-service/MFA product typically deployed as one server per organization serving its entire workforce, so ManageEngine's large overall installed base implies…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.

Vendors
zohocorp
Products
manageengine adselfservice plus
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.