Vulnerability Details CVE-2020-27449
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.5%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2020-27449
-
cpe:2.3:a:zohocorp:manageengine_password_manager_pro:11.1