CVE-2016-1159
MEDIUMZOHO Password Manager Pro 8.3.0-8.4.0 - Exposure of Sensitive Information via Hidden Service
Title source: llmDescription
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
References (4)
Core 4
Core References
Third Party Advisory x_refsource_misc
https://excellium-services.com/cert-xlm-advisory/cve-2016-1159/
Release Notes x_refsource_misc
https://www.manageengine.com/products/passwordmanagerpro/release-notes.html
Third Party Advisory x_refsource_misc
http://jvn.jp/vu/JVNVU90405898/index.html
Vendor Advisory x_refsource_confirm
https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.html
Scores
CVSS v3
6.5
EPSS
0.0037
EPSS Percentile
59.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (2)
zohocorp/manageengine_password_manager_pro
8.3 build8303
zohocorp/manageengine_password_manager_pro
8.4 build8400 (3 CPE variants)
Published
Mar 09, 2020
Tracked Since
Feb 18, 2026