ManageEngine (Exchange Reporter Plus) Product February 2024 Security Update Advisory

Overview

 

Zoho(https://www.zohocorp.com/) has released a security update that addresses a vulnerability in its ManageEngine suite of products. users of affected products are advised to update to the latest version.

 

Affected Products

 

Exchange Reporter Plus build 5714 and earlier

 

Resolved Vulnerabilities

 

High impact SQL injection vulnerability (CVE-2024-21775) in Exchange Reporter Plus [1]

 

Vulnerability Patches

 

According to the security advisory published on February 15th, it is advised to update to the specified version or the latest version.

Exchange Reporter Plus build 5715 version

 

Reference Site

 

[1] CVE-2024-21775 – Authenticated SQL Injection Vulnerability

https://www.manageengine.com/products/exchange-reports/advisory/CVE-2024-21775.html