ZeroHour

CVE-2022-3206

PoC
CVSS 3.1
5.9 medium
EPSS
<1%p40
Published
()
Modified
Description

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

Vendors
passster project
Products
passster
Ecosystems
WordPress
Weakness
CWE-319, CWE-522
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.