Credentials Vulnerability in Zoho ManageEngine Password Manager Pro
CVE-2021-31857

5.9MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
16 June 2021

What is CVE-2021-31857?

A security flaw in Zoho ManageEngine Password Manager Pro allows attackers to exploit a browser extension to retrieve user credentials from non-website resource types. This vulnerability poses significant risks as it enables unauthorized access to sensitive information, highlighting the importance of updating to the latest version, 11.1 build 11104 or higher.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.