CVE-2023-32783: Zohocorp ManageEngine Adaudit Plus
High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."
Affected products
- Zohocorp ManageEngine Adaudit Plus: version 7.1.1 only
Published 2023-08-07. Last modified 2026-06-17.