VendorsZoho Corpmanageengine_password_manager_pro10.0
Vulnerabilities

Zoho Corp ZohoCorp ManageEngine Password Manager Pro 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-40300
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
Published 2022-09-16 · Analyzed
9.8EPSS 0.991
CVE-2020-9347
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products
Published 2020-03-16 · Modified
9.8EPSS 0.078
CVE-2024-5546
SQL Injection
Published 2024-08-28 · Analyzed
8.8EPSS 0.030