ZeroHour

CVE-2025-9428

moderate

Authenticated SQL Injection in ManageEngine Analytics Plus (builds 6171 and prior)

CVSS 3.1
8.8 high
EPSS
26%p98
Published
()
Modified
AI analysis

ManageEngine Analytics Plus build 6171 and earlier contain a SQL injection flaw (CWE-89) in the key update API. A low-privileged, authenticated user can send crafted input to this API endpoint, causing attacker-controlled SQL to execute against the product's backend database. Per the CVSS 8.8 rating, successful exploitation carries high impact on confidentiality, integrity, and availability, meaning an attacker could read, alter, or disrupt the analytics data held by the application. Any organization running an affected build of Analytics Plus is exposed, though exploitation requires valid credentials on the system. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the 25.7% EPSS score (98th percentile) signals an elevated likelihood of exploitation within the next 30 days.

What to do: Upgrade ManageEngine Analytics Plus to a build later than 6171 as directed by ManageEngine's security advisory, and confirm the installed build number in the product before and after patching. Because exploitation requires valid low-privileged credentials, audit which accounts can reach the key update API, restrict that access to trusted users, and review application/database logs for unexpected queries. Given the elevated EPSS, monitor for a public PoC or CISA KEV addition.

Affected
Zoho Corporation ManageEngine Analytics Plusbuilds 6171 and prior
Estimated exposure
moderatelikely on the order of thousands to low tens of thousands of enterprise deployments (no official install-base figure is published) — Analytics Plus is a specialized on-premises BI add-on sold primarily to existing ManageEngine customers — a portfolio used by hundreds of thousands of organizations — and it also ships as embedded analytics within other ManageEngine…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.

Vendors
zohocorp
Products
manageengine analytics plus
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.