SB2023121844 - Multiple vulnerabilities in Zoho Corporation Password Manager Pro
Published: December 18, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: N/A)
The vulnerability allows a local user to escalate privileges within the application.
The vulnerability exists due to improperly imposed security restrictions. A local user with access to default SSH commands and command sets can edit their details
by manipulating a set of commands.
2) Permissions, Privileges, and Access Controls (CVE-ID: N/A)
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improperly imposed security restrictions. A remote user can delete landing servers created by other users.3) Information disclosure (CVE-ID: N/A)
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can obtain the resource owner name.
4) Permissions, Privileges, and Access Controls (CVE-ID: N/A)
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improperly imposed security restrictions. A remote user can update other users' PGP keys, deploy unowned IIS binding info, delete certificate groups of other users.Remediation
Install update from vendor's website.