Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-16T21:42:06
Updated: 2024-08-04T10:26:16.069Z
Reserved: 2020-02-23T00:00:00
Link: CVE-2020-9346
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-03-16T22:15:15.183
Modified: 2022-10-07T00:05:51.477
Link: CVE-2020-9346
Redhat
No data.