← Vulnerability feed

Vulnerability record · CVE-2020-9347 · published 16 March 2020

CVE-2020-9347: Zohocorp manageengine password manager pro csv injection vulnerability

Zohocorp · Manageengine Password Manager Pro

Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products

9.8 CVSS 3.1 Critical EPSS 7.8% · top 5.5% CWE-1236 · CSV injection
9.8CVSS 3.1 base score, v2 7.5
7.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9347 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2022-35405Zoho ManageEngine Password Manager Pro unauthenticated deserialization RCEZoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution via deserializatio…KEVEPSS 100%analysed9.8CVE-2022-47523Zoho ManageEngine PAM products SQL injectionZoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 contain a SQL injection flaw fixed in versions 4309, 12210 and 5801 respective…EPSS 71%analysed9.8CVE-2022-43671Zoho ManageEngine Password Manager Pro, PAM360, Access Manager Plus SQL injectionZoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 are vulnerable to SQL injection. The fla…EPSS 75%analysed9.8CVE-2022-43672Zoho ManageEngine Password Manager Pro, PAM360 and Access Manager Plus SQL injectionZoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 contain a SQL injection flaw in a softwa…EPSS 67%analysed9.8CVE-2022-40300Zoho ManageEngine Password Manager Pro, PAM360 and Access Manager Plus SQL injectionZoho ManageEngine Password Manager Pro (through 12120), PAM360 (through 5550) and Access Manager Plus (through 4304) contain multiple SQL injection v…EPSS 99%analysed9.8CVE-2022-29081Zoho ManageEngine PAM products access-control bypass via path traversalZoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 fail to enforce access control on several REST API endpoints (SSOutAction, SSL…EPSS 84%analysed8.8CVE-2024-5546Zohocorp manageengine pam360 sql injection vulnerabilityZohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injec…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2020-9347), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.