Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7mvq-97q9-r9gg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.

In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.

EPSS

Процентиль: 71%
0.00674
Низкий

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 5.3
nvd
почти 6 лет назад

In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.

EPSS

Процентиль: 71%
0.00674
Низкий

Дефекты

CWE-312