Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3xw2-mcfq-hw9h

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static authentication token if the user is already logged in.

Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static authentication token if the user is already logged in.

EPSS

Процентиль: 1%
0.00011
Низкий

8.1 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.1
nvd
почти 9 лет назад

Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static authentication token if the user is already logged in.

EPSS

Процентиль: 1%
0.00011
Низкий

8.1 High

CVSS3

Дефекты

CWE-295