CVE-2025-9428
moderateAuthenticated SQL Injection in ManageEngine Analytics Plus (builds 6171 and prior)
ManageEngine Analytics Plus build 6171 and earlier contain a SQL injection flaw (CWE-89) in the key update API. A low-privileged, authenticated user can send crafted input to this API endpoint, causing attacker-controlled SQL to execute against the product's backend database. Per the CVSS 8.8 rating, successful exploitation carries high impact on confidentiality, integrity, and availability, meaning an attacker could read, alter, or disrupt the analytics data held by the application. Any organization running an affected build of Analytics Plus is exposed, though exploitation requires valid credentials on the system. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the 25.7% EPSS score (98th percentile) signals an elevated likelihood of exploitation within the next 30 days.
What to do: Upgrade ManageEngine Analytics Plus to a build later than 6171 as directed by ManageEngine's security advisory, and confirm the installed build number in the product before and after patching. Because exploitation requires valid low-privileged credentials, audit which accounts can reach the key update API, restrict that access to trusted users, and review application/database logs for unexpected queries. Given the elevated EPSS, monitor for a public PoC or CISA KEV addition.
| Zoho Corporation ManageEngine Analytics Plus | builds 6171 and prior |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
- Vendors
- zohocorp
- Products
- manageengine analytics plus
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.