Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-3833.html | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    30 Sep 2025, 15:05
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6502:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6513:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6511:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6510:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6500:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6509:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6506:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6507:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6503:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6501:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6512:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6508:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6504:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.5:6505:*:*:*:*:*:* | |
| First Time | Zohocorp manageengine Adselfservice Plus Zohocorp | |
| References | () https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-3833.html - Vendor Advisory | 
16 May 2025, 14:43
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
14 May 2025, 11:16
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-05-14 11:16
Updated : 2025-09-30 15:05
NVD link : CVE-2025-3833
Mitre link : CVE-2025-3833
CVE.ORG link : CVE-2025-3833
JSON object : View
Products Affected
                zohocorp
- manageengine_adselfservice_plus
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
