CVE-2016-3987 | Trend Micro Password Manager Pro HTTP Server openUrlInDefaultBrowser url access control (Exploit 135222 / EDB-39218)
A vulnerability, which was classified as critical, was found in Trend Micro Password Manager Pro. Affected is an unknown function of the file api/openUrlInDefaultBrowser of the component HTTP Server. The manipulation of the argument url leads to improper access controls.
This vulnerability is traded as CVE-2016-3987. It is possible to launch the attack remotely. Furthermore, there is an exploit available.