CVE-2020-9346
EUVD-2020-3016716.03.2020, 22:15
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_password_manager_pro | 𝑥 < 10.4 |
| zohocorp | manageengine_password_manager_pro | 10.4 |
| zohocorp | manageengine_password_manager_pro | 10.4:build10400 |
| zohocorp | manageengine_password_manager_pro | 10.4:build10401 |
| zohocorp | manageengine_password_manager_pro | 10.4:build10402 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References