First published: Wed Jun 16 2021(Updated: )
In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Password Manager Pro | <11.1 | |
Zohocorp Manageengine Password Manager Pro | =11.1 | |
Zohocorp Manageengine Password Manager Pro | =11.1-build_11101 | |
Zohocorp Manageengine Password Manager Pro | =11.1-build_11102 | |
Zohocorp Manageengine Password Manager Pro | =11.1-build_11103 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-31857.
The severity of CVE-2021-31857 is medium with a CVSS score of 5.9.
Zoho ManageEngine Password Manager Pro versions up to 11.1 build 11104 are affected by CVE-2021-31857.
Attackers can exploit CVE-2021-31857 by retrieving credentials via a browser extension for non-website resource types.
Yes, a fix is available for CVE-2021-31857. It is recommended to update Zoho ManageEngine Password Manager Pro to version 11.1 build 11104 or later.