Описание
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.
Ссылки
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:rukovoditel:rukovoditel:2.5.2:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00674
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-522
Связанные уязвимости
github
больше 3 лет назад
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.
EPSS
Процентиль: 71%
0.00674
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-522