High severity8.3NVD Advisory· Published Oct 21, 2025· Updated Jun 17, 2026
CVE-2025-9428
CVE-2025-9428
Description
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:zohocorp:manageengine_analytics_plus:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:*:*:*:*:*:*:*:*range: <6.1
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:6.1:6100:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:6.1:6110:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:6.1:6120:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:6.1:6130:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:6.1:6140:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:6.1:6150:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:6.1:6160:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:6.1:6170:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_analytics_plus:6.1:6171:*:*:*:*:*:*
- (no CPE)range: 0
- Range: <=6171
Patches
Vulnerability mechanics
References
1- www.manageengine.com/analytics-plus/CVE-2025-9428.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.