CVE-2024-5586
HIGHCVSS 8.8/10EPSS 5.17%
Last modified
CVE-2024-5586 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.. EPSS estimates a 5.17% chance of exploitation in the next 30 days.
Description
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Zohocorp | Manageengine Adaudit Plus | <= 8.0 | — |
| Zohocorp | Manageengine Adaudit Plus | 8.1 | 8100 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5586?
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.
How severe is CVE-2024-5586?
CVE-2024-5586 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 5.17% probability of exploitation in the next 30 days.
How do I fix CVE-2024-5586?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-5580Allegra loadFieldMatch Deserialization of Untrusted Data Rem…7.2
- CVE-2024-5581Allegra unzipFile Directory Traversal Remote Code Execution …7.2
- CVE-2024-5582The Schema & Structured Data for WP & AMP plugin for WordPre…5.4
- CVE-2024-5583The The Plus Addons for Elementor – Elementor Addons, Page T…5.4
- CVE-2024-5584The WordPress Online Booking and Scheduling Plugin – Bookly …6.4
- CVE-2024-5585In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.…8.8
- CVE-2024-55864Cross-site scripting vulnerability exists in My WP Customize…4.8
- CVE-2024-5587A vulnerability was found in Casdoor up to 1.335.0. It has b…6.9
- CVE-2024-55875http4k is a functional toolkit for Kotlin HTTP applications.…9.8
- CVE-2024-55876XWiki Platform is a generic wiki platform. Starting in versi…5.4
- CVE-2024-55877XWiki Platform is a generic wiki platform. Starting in versi…8.8
- CVE-2024-55878SimpleXLSX is software for parsing and retrieving data from …6.8
Are you affected by CVE-2024-5586?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
