Introducing ADAudit Plus' Attack Surface Analyzer—Detect 25+ AD attacks and identify risky Azure configurations. Learn more×
 
Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

Security Updates

SQL Injection Vulnerability (CVE-2024-36516) fixed in ADAudit Plus build 8000

Vulnerability details
Severity High
CVE ID CVE-2024-36516
Affected Software Version(s) All ADAudit Plus builds below 8000
Fixed Version Build 8000
Fixed on March 01, 2024

Details

An SQL injection vulnerability in ADAudit Plus' Dashboard has been fixed. This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.

Impact

This vulnerability could allow an authenticated adversary to execute custom queries and access the database table entries using the vulnerable request.

Steps to upgrade

Update your ADAudit Plus instance to the latest build — 8000 — using the service pack.

Acknowledgements

This issue was reported by minhgalaxy.

Please contact support@adauditplus.com for more details.

ADAudit Plus Trusted By