User Credentials Vulnerability in Plone CMS Due to Insecure Cookie Storage
CVE-2008-1394

Currently unrated

Key Information:

Vendor

Plone

Status
Vendor
CVE Published:
20 March 2008

What is CVE-2008-1394?

Plone CMS prior to version 3 exposes a significant security flaw by storing a base64 encoded version of user credentials (username and password) in the __ac cookie for all users. This design choice allows remote attackers to intercept network traffic and easily retrieve sensitive information, posing a severe risk to user account security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.