Total vulnerabilities in the database
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
Software | From | Fixed in |
---|---|---|
zohocorp / manageengine_password_manager_pro | 10.4 | 10.4.x |
zohocorp / manageengine_password_manager_pro | - | 10.4 |
zohocorp / manageengine_password_manager_pro | 10.4-build10400 | 10.4-build10400.x |
zohocorp / manageengine_password_manager_pro | 10.4-build10402 | 10.4-build10402.x |
zohocorp / manageengine_password_manager_pro | 10.4-build10401 | 10.4-build10401.x |