Security Advisory

CVE-2020-9346

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-03-16 21:42:06
Last updated 2024-08-04 10:26:16
Assigner mitre
State PUBLISHED

Description

Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a users role.