logo

Critical Zoho Analytics Plus Flaw Allows Attackers to Run Arbitrary SQL Queries

ID: 9b7dc677-eb3b-527a-a9be-21bc3a71a77b

STIX ID: report--9b7dc677-eb3b-527a-a9be-21bc3a71a77b

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2025-11-14

Date Updated: 2026-04-19

Author: AnuPriya

...
...

A critical unauthenticated SQL injection (CVE-2025-8324) was disclosed in Zoho Analytics Plus on-premise installations (affected builds below 6170), allowing remote attackers to execute arbitrary SQL without authentication and potentially achieve complete database compromise; the issue is fixed in Build 6171. The report outlines the technical root cause (insufficient input validation), the potential impact (exposure of credentials, personal and business data, and account takeover), and notes the high-risk nature of the flaw, though it does not present evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.