Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
References
| Link | Resource |
|---|---|
| https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-3833.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
30 Sep 2025, 15:05
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Zohocorp
Zohocorp manageengine Adselfservice Plus |
|
| References | () https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-3833.html - Vendor Advisory | |
| CPE | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6504:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6500:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6509:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6507:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6512:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6513:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6506:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6510:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6502:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6511:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6505:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6508:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6503:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6501:*:*:*:*:*:* |
16 May 2025, 14:43
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-14 11:16
Updated : 2025-09-30 15:05
NVD link : CVE-2025-3833
Mitre link : CVE-2025-3833
CVE.ORG link : CVE-2025-3833
JSON object : View
Products Affected
zohocorp
- manageengine_adselfservice_plus
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
