Critical Zoho Analytics Plus Flaw Allows Attackers to Run Arbitrary SQL Queries
ID: 9b7dc677-eb3b-527a-a9be-21bc3a71a77b
STIX ID: report--9b7dc677-eb3b-527a-a9be-21bc3a71a77b
Feed Name: Cyber Press
A critical unauthenticated SQL injection (CVE-2025-8324) was disclosed in Zoho Analytics Plus on-premise installations (affected builds below 6170), allowing remote attackers to execute arbitrary SQL without authentication and potentially achieve complete database compromise; the issue is fixed in Build 6171. The report outlines the technical root cause (insufficient input validation), the potential impact (exposure of credentials, personal and business data, and account takeover), and notes the high-risk nature of the flaw, though it does not present evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
