Vulnerability Description
Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.manageengine.com/analytics-plus/CVE-2025-1724.html
- https://www.zoho.com/analytics/onpremise/CVE-2025-1724.html
FAQ
What is CVE-2025-1724?
CVE-2025-1724 is a vulnerability with a CVSS score of 7.4 (HIGH). Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.
How severe is CVE-2025-1724?
CVE-2025-1724 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1724?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.