CVE-2016-1159: Infoleak
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-1159?
CVE-2016-1159 is a vulnerability in ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400, 8401, 8402) that allows underprivileged users to obtain sensitive information via a vulnerable hidden service.
How severe is CVE-2016-1159?
CVE-2016-1159 has a severity rating of 6.5 (Medium).
How can underprivileged users exploit CVE-2016-1159?
Underprivileged users can exploit CVE-2016-1159 to obtain sensitive information (entry password history) via a vulnerable hidden service in ZOHO Password Manager Pro 8.3.0 (Build 8303) and 8.4.0 (Build 8400, 8401, 8402).
Which versions of ZOHO Password Manager Pro are affected by CVE-2016-1159?
ZOHO Password Manager Pro 8.3.0 (Build 8303) and 8.4.0 (Build 8400, 8401, 8402) are affected by CVE-2016-1159.
Are there any fixes or patches available for CVE-2016-1159?
Yes, fixes for CVE-2016-1159 are available on the ZOHO Password Manager Pro website.