Описание
The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.5.5.5.2 (исключая)
cpe:2.3:a:passster_project:passster:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 42%
0.00198
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-319
Связанные уязвимости
CVSS3: 5.9
github
больше 3 лет назад
The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.
EPSS
Процентиль: 42%
0.00198
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-319