CVE Details
Basic Information
| Title | CVE-2025-3836 SQL Injection |
|---|---|
| Type | cve |
| Published | 2025-05-22T10:38:26 |
| Last Seen | 2025-05-22T11:14:12 |
CVSS Information
| Base Score | 8.3 (HIGH) |
|---|---|
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | LOW |
AI Analysis
| AI Description | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events. This allows attackers to execute arbitrary SQL commands, potentially compromising the database. The vulnerability is due to improper input validation in the web application. |
|---|---|
| AI Severity | High |
| Vendor | Zohocorp |
| Product | ManageEngine ADAudit Plus |
| Affected Version | 8510 and prior |
Additional Information
| CVE List | CVE-2025-3836 |
|---|---|
| CWE List | CWE-89 |
| Bulletin Family | cve |
Description
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events…
CVSS Score Summary
Base Score: %!f(string=#) (HIGH)