Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j63-969g-r2jp

Опубликовано: 17 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

EPSS

Процентиль: 42%
0.00198
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-319
CWE-326

Связанные уязвимости

CVSS3: 5.9
nvd
больше 3 лет назад

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

EPSS

Процентиль: 42%
0.00198
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-319
CWE-326