CVE-2023-48792: Zohocorp ManageEngine Adaudit Plus

Critical severity, CVSS 9.8. EPSS: 7% chance of exploitation in the next 30 days.

Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.

Affected products

  • Zohocorp ManageEngine Adaudit Plus: before 7.2 (fixed in 7.2); version 7.2 only

Published 2024-02-02. Last modified 2026-06-17.