CVE-2020-9346
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attack
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
HIGH · CVSS 8.8
EPSS 0.00447
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0