CVE-2025-8324 Details
Description
Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.
A critical unauthenticated SQL injection vulnerability has been identified in ManageEngine Analytics Plus on-premise versions through 6170. This vulnerability arises from improper input validation, allowing attackers to execute arbitrary SQL queries. Exploitation of this issue could lead to unauthorized access to user information and potential account takeovers.
Users can upgrade to the latest version by downloading the upgrade pack from the ManageEngine Analytics Plus service pack page and following the provided upgrade instructions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 11, 2025CISA-ADP
Assessed Nov 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/analytics-plus/CVE-2025-8324.html | ManageEngine | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | ManageEngine |
Affected Products
| Product | Versions |
|---|---|
| ManageEngine Analytics Plus | < 6170 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 11, 2025 | New CVE Received | ManageEngine |
Volerion