Vulnerabilities > Zohocorp > Manageengine Password Manager PRO > 9.0

DATE CVE VULNERABILITY TITLE RISK
2020-03-16 CVE-2020-9346 Cross-Site Request Forgery (CSRF) vulnerability in Zohocorp Manageengine Password Manager PRO
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
network
low complexity
zohocorp CWE-352
8.8
2017-12-15 CVE-2017-17698 Cross-site Scripting vulnerability in Zohocorp Manageengine Password Manager PRO
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
network
low complexity
zohocorp CWE-79
6.1