CVE-2020-27449
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
Affected (1)
Products: Zohocorp: Manageengine Password Manager Pro
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1 build_11101 |
References (4)
Source: cve@mitre.org
Permissions RequiredVendor Advisory
Source: cve@mitre.org
ProductRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductRelease Notes
Timeline
No history available yet.