CVE-2025-1724

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Mar 17, 2025
CWE ID 798

Summary

CVE-2025-1724 identifies a vulnerability affecting the on-premise versions of Zohocorp's ManageEngine Analytics Plus and Zoho Analytics. These outdated software editions contain a hardcoded sensitive token, making them susceptible to account takeover attacks via Active Directory (AD) authentication. Successful exploitation of this vulnerability allows an attacker to gain administrative access to these systems, potentially compromising sensitive data or functionality. Organizations using these affected versions are advised to apply the necessary patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share