Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_adselfservice_plus | - | 6.5 |
| zohocorp / manageengine_adselfservice_plus | 6.5-6500 | 6.5-6500.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6501 | 6.5-6501.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6502 | 6.5-6502.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6503 | 6.5-6503.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6504 | 6.5-6504.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6505 | 6.5-6505.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6506 | 6.5-6506.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6507 | 6.5-6507.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6508 | 6.5-6508.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6509 | 6.5-6509.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6510 | 6.5-6510.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6511 | 6.5-6511.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6512 | 6.5-6512.x |
| zohocorp / manageengine_adselfservice_plus | 6.5-6513 | 6.5-6513.x |