CVE-2025-1724: Zohocorp Analytics Plus
High severity, CVSS 7.4. EPSS: 1.3% chance of exploitation in the next 30 days.
Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.
Affected products
- Zohocorp Analytics Plus: before 6130 (fixed in 6130)
Published 2025-03-17. Last modified 2026-06-17.