ZeroHour

CVE-2020-27449

CVSS 3.1
6.1 medium
EPSS
3%p87
Published
()
Modified
Description

Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.

Vendors
zohocorp
Products
manageengine password manager pro
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.