Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wxc-phqq-75fh

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to the "Settings - Account Information" tab.

member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to the "Settings - Account Information" tab.

EPSS

Процентиль: 45%
0.00225
Низкий

Связанные уязвимости

nvd
около 17 лет назад

member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to the "Settings - Account Information" tab.

EPSS

Процентиль: 45%
0.00225
Низкий