PT-2009-6509 · Manageengine · Manageengine Password Manager Pro

Stefan Friedli

·

Published

2009-12-22

·

Updated

2009-12-23

·

CVE-2009-4387

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine Password Manager Pro (PMP) versions prior to 6.1 Build 6104
Description The issue concerns a flaw in the cross-site scripting (XSS) protection mechanism. This flaw allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified inputs, due to the use of case-sensitive checks for malicious inputs.
Recommendations For versions prior to 6.1 Build 6104, update to version 6.1 Build 6104 or later to resolve the issue. As a temporary workaround, consider restricting access to the searchtext parameter in the affected API endpoint until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4387

Affected Products

Manageengine Password Manager Pro