CVE-2008-1393

EPSS 1.7%

Plone Improper Session Management

Published: 5/1/2022Modified: 5/19/2024
Also known as:GHSA-593c-j348-f3gv

Description

Plone CMS before 3, places a base64 encoded form of the username and password in the `__ac` cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.

Affected packages (1)

References (8)