Vulnerability Description
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Password Manager Pro | < 10.4 |
Related Weaknesses (CWE)
References
- https://www.infigo.hr/upload/web_struktura/Zoho_ManageEngine_Password_Manager_PrThird Party Advisory
- https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.htmlIssue TrackingVendor Advisory
- https://www.infigo.hr/upload/web_struktura/Zoho_ManageEngine_Password_Manager_PrThird Party Advisory
- https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.htmlIssue TrackingVendor Advisory
FAQ
What is CVE-2020-9346?
CVE-2020-9346 is a vulnerability with a CVSS score of 8.8 (HIGH). Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
How severe is CVE-2020-9346?
CVE-2020-9346 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9346?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Password Manager Pro.