PT-2020-8016 · Zoho · Zoho Password Manager Pro

Published

2020-03-09

·

Updated

2020-03-10

·

CVE-2016-1159

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ZOHO Password Manager Pro (PMP) versions 8.3.0 through 8.4.0
Description: The issue allows underprivileged users to obtain sensitive information, specifically entry password history, via a vulnerable hidden service.
Recommendations: For versions 8.3.0 and 8.4.0, consider restricting access to the hidden service until a fix is available. As a temporary workaround, limit the privileges of underprivileged users to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1159

Affected Products

Zoho Password Manager Pro