CVE-2021-31857: Medium severity manageengine password manager pro vulnerability
Published Jun 16, 2021
·Updated
In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.
Affected Software
5 affected components
ZohoCorp ManageEngine Password Manager Pro<11.1
ZohoCorp ManageEngine Password Manager Pro=11.1
ZohoCorp ManageEngine Password Manager Pro=11.1-build_11101
ZohoCorp ManageEngine Password Manager Pro=11.1-build_11102
ZohoCorp ManageEngine Password Manager Pro=11.1-build_11103
Event History
Jun 16, 2021
CVE Published
via MITRE·12:45 PM
Data Sourced
via MITRE·12:45 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-31857.
2
What is the severity of CVE-2021-31857?
The severity of CVE-2021-31857 is medium with a CVSS score of 5.9.
3
Which software is affected by CVE-2021-31857?
Zoho ManageEngine Password Manager Pro versions up to 11.1 build 11104 are affected by CVE-2021-31857.
4
How can attackers exploit CVE-2021-31857?
Attackers can exploit CVE-2021-31857 by retrieving credentials via a browser extension for non-website resource types.
5
Is there a fix available for CVE-2021-31857?
Yes, a fix is available for CVE-2021-31857. It is recommended to update Zoho ManageEngine Password Manager Pro to version 11.1 build 11104 or later.