CVE-2020-27449: Zohocorp ManageEngine Password Manager Pro

Medium severity, CVSS 6.1. EPSS: 3.1% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.

Affected products

  • Zohocorp ManageEngine Password Manager Pro: version 11.1 only

Published 2023-08-11. Last modified 2026-06-17.