Medium severity6.1NVD Advisory· Published Aug 11, 2023· Updated Jun 17, 2026
CVE-2020-27449
CVE-2020-27449
Description
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:zohocorp:manageengine_password_manager_pro:11.1:build_11101:*:*:*:*:*:*
- Zoho/ManageEngine Password Manager Prodescription
- Range: = 11001
- Range: = 11001
Patches
Vulnerability mechanics
References
2- bugbounty.zoho.com/bb/nvdPermissions RequiredVendor Advisory
- www.manageengine.com/products/passwordmanagerpro/release-notes.htmlnvdProductRelease Notes
News mentions
0No linked articles in our index yet.