Vulnerability Description
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Password Manager Pro | 10.0 |
Related Weaknesses (CWE)
References
- https://www.infigo.hr/upload/web_struktura/Zoho_ManageEngine_Password_Manager_PrThird Party Advisory
- https://www.infigo.hr/upload/web_struktura/Zoho_ManageEngine_Password_Manager_PrThird Party Advisory
FAQ
What is CVE-2020-9347?
CVE-2020-9347 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the s...
How severe is CVE-2020-9347?
CVE-2020-9347 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-9347?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Password Manager Pro.