CVE-2020-9346: CSRF
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9346?
CVE-2020-9346 is a vulnerability in Zoho ManageEngine Password Manager Pro 10.4 and prior that allows for Cross-site Request Forgery (CSRF) attacks.
What is the severity of CVE-2020-9346?
The severity of CVE-2020-9346 is high, with a CVSS score of 8.8.
How does CVE-2020-9346 affect Zoho ManageEngine Password Manager Pro?
CVE-2020-9346 affects Zoho ManageEngine Password Manager Pro 10.4 and prior versions by not providing protection against CSRF attacks, allowing for unauthorized changes to a user's role.
How can I fix CVE-2020-9346 in Zoho ManageEngine Password Manager Pro?
To fix CVE-2020-9346, users should update to a version of Zoho ManageEngine Password Manager Pro that includes the necessary protection against CSRF attacks.
Where can I find more information about CVE-2020-9346?
More information about CVE-2020-9346 can be found in the provided references: https://www.infigo.hr/upload/web_struktura/Zoho_ManageEngine_Password_Manager_Pro_10.4_CSRF.txt and https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.html