Описание
Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.
Ссылки
- Exploit
- ExploitVendor Advisory
- Exploit
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.1 (включая)
cpe:2.3:a:citrix:program_neighborhood_client:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00086
Низкий
2.1 Low
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.
EPSS
Процентиль: 25%
0.00086
Низкий
2.1 Low
CVSS2
Дефекты
NVD-CWE-Other