CVE Details
Basic Information
| Title | CVE-2025-41407 |
|---|---|
| Type | cve |
| Published | 2025-05-23T11:15:33 |
| Last Seen | 2025-05-23T12:27:18 |
CVSS Information
| Base Score | 8.3 (HIGH) |
|---|---|
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | LOW |
AI Analysis
| AI Description | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection attacks due to improper input validation. This allows authenticated attackers to execute arbitrary SQL commands, potentially compromising the database. |
|---|---|
| AI Severity | High |
| Vendor | Zohocorp |
| Product | ManageEngine ADAudit Plus |
| Affected Version | Below 8511 |
Additional Information
| CVE List | CVE-2025-41407 |
|---|---|
| CWE List | CWE-89 |
| Bulletin Family | cve |
Description
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL…
CVSS Score Summary
Base Score: %!f(string=#) (HIGH)