CVE-2025-3833: Zohocorp ManageEngine Adselfservice Plus

High severity, CVSS 8.1. EPSS: 46.6% chance of exploitation in the next 30 days.

Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.

Affected products

  • Zohocorp ManageEngine Adselfservice Plus: before 6.5 (fixed in 6.5); version 6.5 only

Published 2025-05-14. Last modified 2026-06-17.