CVE-2008-1393

EPSS 1.7%

Plone Improper Session Management

發布日:2022/5/1修改日:2024/5/19

描述

Plone CMS before 3, places a base64 encoded form of the username and password in the `__ac` cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.

受影響套件(1)

參考連結(8)