Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f465-339w-2vhm

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.

The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.

EPSS

Процентиль: 43%
0.00204
Низкий

7.5 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 7.5
nvd
больше 23 лет назад

The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.

CVSS3: 7.5
debian
больше 23 лет назад

The default "basic" security setting' in config.php for TWIG webmail 2 ...

EPSS

Процентиль: 43%
0.00204
Низкий

7.5 High

CVSS3

Дефекты

CWE-312