Vulnerability record · CVE-2025-3833 · published 14 May 2025
CVE-2025-3833: ManageEngine ADSelfService Plus authenticated SQL injection in MFA reports
Zohocorp · Manageengine Adselfservice Plus
ManageEngine ADSelfService Plus versions 6513 and prior contain an authenticated SQL injection flaw in the MFA reports component. A logged-in user can inject SQL through that reporting interface, which matters because it exposes backend data and integrity to a low-privileged account.
Description
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Automated analysis
high priorityHigh CVSS (8.1) with high confidentiality and integrity impact and very high EPSS, though it requires authentication and no active exploitation is documented.
What it is
ManageEngine ADSelfService Plus versions 6513 and prior contain an authenticated SQL injection flaw in the MFA reports component. A logged-in user can inject SQL through that reporting interface, which matters because it exposes backend data and integrity to a low-privileged account.
Impact
An authenticated attacker can read and modify data reachable by the application's database queries, giving high confidentiality and integrity impact. Availability is not affected per the CVSS vector.
Attack surface
Reachable over the network through the MFA reports feature; the CVSS vector shows low privileges required and no user interaction. Authentication is required, so the attacker needs a valid account.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record. EPSS is 0.45156 (98.7th percentile), indicating elevated predicted exploitation likelihood.
What to do
- Upgrade ADSelfService Plus to a version later than 6513 per the vendor advisory.
- If immediate upgrade is not possible, restrict access to the MFA reports feature to trusted administrators only.
- Review and minimize accounts with access to MFA reporting to reduce the authenticated attack surface.
- Monitor database and application logs for anomalous SQL in MFA report requests.
- Apply least-privilege permissions to the database account used by ADSelfService Plus.
Detection
- Search application and web logs for SQL metacharacters or UNION/boolean patterns in MFA report parameters.
- Alert on MFA report queries returning unusually large result sets or errors from malformed SQL.
- Baseline normal MFA report usage per account and flag deviations from low-privileged users.
- Correlate database audit logs with ADSelfService Plus report activity for unexpected table access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-3833.html | Vendor Advisory |
Track CVE-2025-3833 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-3833), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.