Page 2 of 11 results (0.000 seconds)

CVSS: 8.8EPSS: 0%CPEs: 5EXPL: 0

16 Mar 2020 — Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role. Zoho ManageEngine Password Manager Pro versiones 10.4 y anteriores, no poseen protección contra ataques de tipo Cross-site Request Forgery (CSRF), como es demostrado al cambiar el rol del usuario. • https://www.infigo.hr/upload/web_struktura/Zoho_ManageEngine_Password_Manager_Pro_10.4_CSRF.txt • CWE-352: Cross-Site Request Forgery (CSRF) •