Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
References
Configurations
Information
Published : 2015-06-08 17:59
Updated : 2016-12-30 18:59
NVD link : CVE-2015-4418
Mitre link : CVE-2015-4418
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
zohocorp
- manageengine_netflow_analyzer