vendor:
ManageEngine Password Manager Pro
by:
Anonymous
8,8
CVSS
HIGH
Stored XSS, Privilege escalation, Business Login Bypass, Password policy bypass, Horizontal privilege escalation, Resource's user enumeration, Password Bruteforce, Cross-Site Request Forgery
N/A
CWE
Product Name: ManageEngine Password Manager Pro
Affected Version From: 8102
Affected Version To: 8302
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Multiple Vulnerabilities in ManageEngine Password Manager Pro
Multiple vulnerabilities were identified within ManageEngine Password Manager Pro, a secure vault for storing and managing shared sensitive information such as passwords, documents and digital identities of enterprises. These vulnerabilities include Stored XSS in /AddMail.ve, Privilege escalation in /EditUser.do, Business Login Bypass in /EditUser.do, Password policy bypass in /jsp/xmlhttp/AjaxResponse.jsp, Horizontal privilege escalation in /jsp/xmlhttp/AjaxResponse.jsp, Resource's user enumeration in /jsp/xmlhttp/PasswdRetriveAjaxResponse.jsp, Password Bruteforce for resources accounts in /jsp/xmlhttp/AjaxResponse.jsp, and Cross-Site Request Forgery.
Mitigation:
Password Manager Pro Release 8.3 (8300) (Released on October, 2015) fix issues #2, #4, #7 and partially #8. Password Manager Pro Release 8.3 (8303) (Released on December 2015) fix issues #1, #3, #5 and #6.