CVE-2024-21791: Zohocorp ManageEngine Adaudit Plus
High severity, CVSS 7.2. EPSS: 2.2% chance of exploitation in the next 30 days.
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.
Affected products
- Zohocorp ManageEngine Adaudit Plus: before 7.2 (fixed in 7.2); version 7.2 only
Published 2024-05-22. Last modified 2026-06-17.